Hello,
I have log in the format
"2021-02-18T16:17:12,189Z [main] INFO logname -streamstart-k1:V1,K2:V2,K3:V3,streamstop, <ADDIITONAL DATA>" i want to parse out json elements k1:v1 etc thats between "-streamstart" and streamstop
Try this
rex "streamstart(?<myvariable>(.*)(?=streamstop))"
it does the job but still dosent index the fields its extracted it out to the variable can we somehow index these csv values
This gives me what i want but i am unable to index it in splunk
(?<=streamstart-).*?(?=streamstop)
Hi @vashodha
Yes. Data extracted using rex in the search time will only be available for the search. You need to follow series of steps based on your Splunk solution for creating fields at Index time.
Please refer the below article.