I have following data after this query:
index=sdlocp_epo-solutiontest sourcetype="kube:container:customer-soap-app"
| spath
| search level="SERVICE_PERF"
| table message
|2800|BackOffice|T999999||Servcie1|8b81dbd0-ba0f-11e9-8912-914decccd432|Success|67|NA|NA|NA
|2800|BackOffice|T999999||Servcie1|8b81dbd0-ba0f-11e9-8912-914decccd432|Success|67|NA|NA|NA
|2800|BackOffice|T999999||Servcie1|8b81dbd0-ba0f-11e9-8912-914decccd432|Success|67|NA|NA|NA
|2800|BackOffice|T999999||Servcie2|8b81dbd0-ba0f-11e9-8912-914decccd432|Success|16|NA|NA|NA
|2800|BackOffice|T999999||Servcie2|8b81dbd0-ba0f-11e9-8912-914decccd432|Success|16|NA|NA|NA
|2800|BackOffice|T999999||Servcie2|8b81dbd0-ba0f-11e9-8912-914decccd432|Success|16|NA|NA|NA
I then run the following query:
index=sdlocp_epo-solutiontest sourcetype="kube:container:customer-soap-app"
| spath
| search level="NG_SERVICE_PERFORMANCE"
| table message
| eval fields=split(message,"|") , etime=mvindex(fields,8)
| table etime
It fails.
When I run it with _raw instead of message in split, it works. Why is that so?
I am using logs in JSON format.
Thanks in advance.
... View more