My logs are in the format: My-Application Log: Some-Key= 99, SomeOtherKey= 231, SomeOtherKey2= 1231, Some Different Key= 0, Another Key= 121 I currently use query: index="myindex" "My-Application Log:" | extract pairdelim=", " kvdelim="= " | table Some-Key SomeOtherKey SomeOtherKey2 "Some Different Key" "Another Key" It is able to extract events however the table is filled with blank/null values. How can i visualise the data if i have this format of logs. I have to group by Some-key. Example visualization should be grouped basis Some-key Thanks in advance.
... View more