Splunk Search

Why is the "multikv" command not extracting fields in Splunk 6.4.2?


i have created some visualizations in my local Splunk (6.5.1) for vmstat,sar,sar2,iostat etc. when i use multikv in search, i see fields are extracting.

when i implement the same in actual Splunk machine (6.4.2) with multikv, fields are not extracting.

i am attaching the indexed logs. any help is appreciated.

0 Karma

Esteemed Legend

Download the *Nix TA App from SplunkBase and see how it handles the inputs from these commands and copy it (or just use the TA).

0 Karma