Hello splunkers!
I have event in this format:
id_param1,id_value1,id_param2,id_value2,...,id_paramX,id_valueX
for example:
2,45,3,14,31,8,4356,abcd,4421,3,9,foo
I need to transform this into key-value pair:
2 45
3 14
31 8
4356 abcd
4421 3
9 foo
How I can make it by rex in Splunk?
Best regards,
Roman
Try this:
| yoursearch
| rex field=_raw max_match=0 "(?<key>[^\,]++)\,(?<value>[^\,]++)\,?"
| eval keyvalues = mvzip(key,value)
Try this:
| yoursearch
| rex field=_raw max_match=0 "(?<key>[^\,]++)\,(?<value>[^\,]++)\,?"
| eval keyvalues = mvzip(key,value)
Great!!!
Thank you very much, it's working!
Best regards,
Roman