I added the following to the props.conf and do not see any difference in Splunk, (no defined fields) nor does the search provided produce any results.
[wily_reports]
SHOULD_LINEMERGE=false
EXTRACT-fe1=(?.*?)Average Response Time \(ms\)\s*\,(?\d+)\,(?.*?)\,
DATETIME_CONFIG = CURRENT
Attached is a copy and paste of an event displayed currently.
Client2 Weekly Phil Report,,,,,
WEB Server 1 & 2 Frontends ART (ms),,,,,
WEB Servers 1-6 Frontends ART (ms),,,,Mean,Count
server1|Tomcat|Client2Prod|Frontends|Apps|WebClient:Average Response Time (ms),,,,32,1.9M
server2|Tomcat|Client2Prod|Frontends|Apps|WebClient:Average Response Time (ms),,,,31,1.8M
server3|Tomcat|Client2Prod|Frontends|Apps|WebClient:Average Response Time (ms),,,,36,2.6M
server4|Tomcat|Client2Prod|Frontends|Apps|WebClient:Average Response Time (ms),,,,63,2.3M
server5|Tomcat|Client2Prod|Frontends|Apps|WebClient:Average Response Time (ms),,,,34,2.3M
server6|Tomcat|Client2Prod|Frontends|Apps|WebClient:Average Response Time (ms),,,,34,2.1M
Again, if I try to extract a field (mean) for more than two values above, I get a "Field names must be unique." Is there a way I can break up these results into individual lines (events) so I can create the field without the conflict since they are all in the same event?
... View more