Hi,
i have created some visualizations in my local Splunk (6.5.1) for vmstat,sar,sar2,iostat etc. when i use multikv
in search, i see fields are extracting.
when i implement the same in actual Splunk machine (6.4.2) with multikv
, fields are not extracting.
i am attaching the indexed logs. any help is appreciated.
Download the *Nix TA App from SplunkBase and see how it handles the inputs from these commands and copy it (or just use the TA).