Hey Splunk Experts,
I have a log that produce something like below; (Notice there is a key named source[not the splunk source])
timestamp source=graph name=standard
...
When I table the above log ; | table source name ; It shows source as in the log file path.
source name
/opt/app/abc.log standard
Is there a way to escape that so it shows value in log file - like below? Thank you!
source name
graph standard
Hello @charmsstyler ,
try search time extraction
.... |rex "\s+source=(?<source_orig>[^\s]+)" | table source_orig name
Hello @charmsstyler ,
try search time extraction
.... |rex "\s+source=(?<source_orig>[^\s]+)" | table source_orig name