Splunk Search

split filed into multiple filed

abhijeet
Explorer

I would like to break "X" field into multiple field based on available value. "X" contain data in following format. 

Field X-

ABC: YES, APPLICATION: DEF, ZONE: DATA, ENVIRONMENT: DEV

ZONE: INSIDE, ENVIRONMENT: PROD

ZONE: OUTSIDE, ENVIRONMENT: DEV, ABC: YES, APPLICATION: IJK

=======

I would like the arrange data in following format.

 

ABC     APPLICATION             ZONE           ENVIRONMENT

YES           DEF                          DATA                      DEV

                                                     INSIDE                  PROD

YES           IJK                           OUTSIDE             DEV

 

TIA. 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The bit before the blank lines just sets up dummy data for the runanywhere example

| makeresults 
| eval X=split("ABC: YES, APPLICATION: DEF, ZONE: DATA, ENVIRONMENT: DEV|ZONE: INSIDE, ENVIRONMENT: PROD|ZONE: OUTSIDE, ENVIRONMENT: DEV, ABC: YES, APPLICATION: IJK","|")
| mvexpand X


| eval _raw=X
| extract pairdelim="," kvdelim=":"

 

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

The bit before the blank lines just sets up dummy data for the runanywhere example

| makeresults 
| eval X=split("ABC: YES, APPLICATION: DEF, ZONE: DATA, ENVIRONMENT: DEV|ZONE: INSIDE, ENVIRONMENT: PROD|ZONE: OUTSIDE, ENVIRONMENT: DEV, ABC: YES, APPLICATION: IJK","|")
| mvexpand X


| eval _raw=X
| extract pairdelim="," kvdelim=":"

 

abhijeet
Explorer

Thank you so much. Solution works... 

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...