Getting Data In

Extract field values

shangshin
Builder

Hi, I have having the following stanza in transforms.conf

[apache_fields]
DELIMS = "\t"
FIELDS = clientip,remotelogname,user_id,timestamp,resource_requested,http_status_code,content_length,referrer,user_agent,response_time

clientip field value could be 1 or 2 IP separated by comma
10.39.127.164
10.39.127.164, 10.183.135.2

Is it possible to add another stanza so I can extract ip1 and ip2 if it exists.

Thanks in advance!

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Have you considered replacing the DELIMS and FIELDS statements with a REGEX? For example:

[apache_fields]
REGEX = (?<ip1>.*?)(,\s(?<ip2>.*?))?\s(?<remotelogname>.*?)\s(?<user_id>.*?)\s(?<timestamp>.*?)\s(?<resource_requested>.*?)\s(?<http_status_code>.*?)\s(?<content_length>.*?)\s(?<referrer>.*?)\s(?<user_agent>.*?)\s(?<response_time>.*)
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Have you considered replacing the DELIMS and FIELDS statements with a REGEX? For example:

[apache_fields]
REGEX = (?<ip1>.*?)(,\s(?<ip2>.*?))?\s(?<remotelogname>.*?)\s(?<user_id>.*?)\s(?<timestamp>.*?)\s(?<resource_requested>.*?)\s(?<http_status_code>.*?)\s(?<content_length>.*?)\s(?<referrer>.*?)\s(?<user_agent>.*?)\s(?<response_time>.*)
---
If this reply helps you, Karma would be appreciated.

shangshin
Builder

Thank you. This works!

0 Karma

shangshin
Builder

yes, the delimiter is comma. I tried to add a new stanza below but it didn't work out. Thank you!

[clientip]
DELIMS = ", "
FIELDS = aip1, aip2

0 Karma

lukejadamec
Super Champion

So, there is white space for a delimiter, but only a comma between the IPs?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...