There is now a conflict between the corrected mock data and the emulation pseudo code. The former seems to imply that Component contains what you want as Field-Type, but the latter directly uses Fie...
See more...
There is now a conflict between the corrected mock data and the emulation pseudo code. The former seems to imply that Component contains what you want as Field-Type, but the latter directly uses Field-Type as field name. Let's take baby steps. First, can you confirm that your _raw events look like, or contain something like the following emulation? In other words, the mock data you give, are they emulating _raw? | makeresults
| eval data=split("Component=F_Type_1,.....,Section_5=F_Type_1_Section_5_Value
Component=F_Type_2,.....,Section_5=F_Type_2_Section_5_Value
Component=F_Type_3,.....,Section_5=F_Type_3_Section_5_Value", "
")
| mvexpand data
| rename data AS _raw
``` emulation assuming Splunk "forgets" to extract ``` _raw _time Component=F_Type_1,.....,Section_5=F_Type_1_Section_5_Value 2024-02-14 11:10:02 Component=F_Type_2,.....,Section_5=F_Type_2_Section_5_Value 2024-02-14 11:10:02 Component=F_Type_3,.....,Section_5=F_Type_3_Section_5_Value 2024-02-14 11:10:02 (See how similar this is from my previous emulation? You can simply adopt the formula with the field names.) Whether you use forwarder or some other mechanism to ingest data is not a factor in Splunk extraction. But if Splunk does NOT give Component and Section_5, you should dig deeper with admin. Maybe post the props.conf that contains this source type. You can always run | extract with _raw. But it it would be so much better if you don't have to. TimeStamp Component=F_Type_1,.....,Section_5=F_Type_1_Section_5_Value Component=F_Type_2,.....,Section_5=F_Type_2_Section_5_Value Component=F_Type_3,.....,Section_5=F_Type_3_Section_5_Value Or, do you mean all these 3 (and more) lines form one single _raw event? In other words, does this emulation better resembles your _raw events? | makeresults
| eval _raw="TimeStamp
Component=F_Type_1,.....,Section_5=F_Type_1_Section_5_Value
Component=F_Type_2,.....,Section_5=F_Type_2_Section_5_Value
Component=F_Type_3,.....,Section_5=F_Type_3_Section_5_Value" _raw _time TimeStamp Component=F_Type_1,.....,Section_5=F_Type_1_Section_5_Value Component=F_Type_2,.....,Section_5=F_Type_2_Section_5_Value Component=F_Type_3,.....,Section_5=F_Type_3_Section_5_Value 2024-02-14 11:20:05