I had the exact same problem as you, and I solved it by a slight modification of your attempt: index=xyz | rename _raw AS _temp message AS _raw | extract kvdelim="=" pairdelim=" " | table offerId, productId As extract only can read from _raw, you need to rename the field you want to extract key value pairs from to _raw. See https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/SearchReference/Extract for more info
... View more