Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Best Sourcetype for KV pair

$
0
0
1- How to define the KV pair and delimitation in the source type ? the extract has this form (with 15 KV) k1="v1", k2="v2", ... 2- What extract form do you recommend (JSON ?) 3- is | extract pairdelim=", " kvdelim="=" as fast as define that in the source type ? thks for your help :-)

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>