Automatic field extraction is probably one of my favorite perks of throwing data into Splunk... but interestingly enough, it's causing a bit of an annoyance in this case.
I have a log that looks more or less like this:
Time: 01/02/13 01:02:58 PM
Execution Time (ms): 0.234943
Statement Text: SELECT foo, bar FROM table t WHERE t.foo="blah" AND t.bar="something"
Pretty straight-forward - but Splunk decided to extract key/value pairs from the SQL query. Above is a rather simple query.. but the real log contains some pretty large ones with column names all over the place, thus making the "X interesting fields" list HUGE and almost impossible to find the actual fields we want to extract.
If you don't mind extracting the KV pairs manually for this data, you can set KV_MODE=none
in props.conf for the source/sourcetype.
If you don't mind extracting the KV pairs manually for this data, you can set KV_MODE=none
in props.conf for the source/sourcetype.
Just what I was looking for - thanks!