Hey Splunk Experts,
I have a log that produce something like below; (Notice there is a key named source[not the splunk source])
timestamp source=graph name=standard
When I table the above log ; | table source name ; It shows source as in the log file path.
Is there a way to escape that so it shows value in log file - like below? Thank you!
Hello @charmsstyler ,
try search time extraction
.... |rex "\s+source=(?<source_orig>[^\s]+)" | table source_orig name
View solution in original post