- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
minkyuk
Explorer
07-08-2015
07:51 AM
Hello-
I'll jump into the main part.
Here is a snippet:
Tue 2015 15:00:23
ZGD-OCU-QQQ
POS-BKD-AKD
COK-ZPP-AKF
DISK-------USAGE-------HOST
My multikv extraction thinks "ZGD-OCU-QQQ" is my "fields".
It definitely is correctly extracting the information, but I'm trying to find a way to skip 3 lines-rows- after the timestamp to extract correct fields.
I would appreciate any help..!
J
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
07-08-2015
08:36 AM
Try ... | multikv start_line=4 ...
. Adjust the start_line value as necessary.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
07-08-2015
08:36 AM
Try ... | multikv start_line=4 ...
. Adjust the start_line value as necessary.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
minkyuk
Explorer
07-08-2015
11:48 AM
I still need to read the first line to record the Timestamp, however.
Could I use any variation?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
07-08-2015
11:52 AM
Use rex
to extract the timestamp before using multikv
on the rest.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
