Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How do I configure Splunk to recognize my custom delimiter for proper field extraction?

$
0
0
I currently have a log statement which has a custom delimiter: `{|}` Where an example log statement would look like: Oct-13 12:17:13 | INFO| [Logger:152] Message{|}Activity1{|}userDeletedProfile{|}John Smith{|}Smith Securities{|}Test1{|}5512{|}324166{|}552341{|}260 However, when I try to conduct a field extraction where `DELIMS = "{|}"`, the fields aren't being extracted properly. However, testing the above log statement in another application that is capable of delimiting yields successful results.

Viewing all articles
Browse latest Browse all 1485


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>