Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

one event one filed multi value

$
0
0

hello I have my log form as multi lines breaked with an empty line thanks to ziegfried, I have devided each event successfully with his help now I want to extract a field, in each event, may covers more than one value. 1,2 maybe 3 of them, same REX.

I find slpunk can pick out the first value which match the REX express, the others are dropped. Can splunk extract multi values in one event with one REGEX or one FIELD name? Thank you!


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>