|
I've got a lot of CSV data that I'm indexing and for one of the fields in the csv, the values are themselves big jumbles of different fields joined together. eg:
The http://www.splunk.com/base/Documentation/latest/SearchReference/Extract Right now I'm thinking of:
but it seems really clunky and I thought maybe there's a better way. |
|
If you don't want to tackle it via conf - I'll see your clunky and raise you one (sans _raw)
1
Close. But the performance of xmlkv on the number of events I need, is pretty horrendous. In fact a nice little warning pops up in the 4.3 UI, telling me I'm insane to send this many events through xmlkv. =)
(01 Feb, 23:14)
nick ♦
|
