ABCD is also my suggestion as in m Fundamentals 2 PDF dated Jan 2021, Delimiters used in events is Space, Comma, Tab Pipe and Other (which can be colons)
ABCD
A. Tabs: Tabs can be used as delimiters for field extraction in Splunk. They are commonly used when data is separated by tab characters.
B. Pipes: Pipes (|) can be used as delimiters in Splunk's Field Extractor. This is especially useful when data is structured using pipe characters as separators.
C. Colons: Colons (:) can also be used as delimiters when defining field extractions in Splunk. If your data is separated by colons, you can specify this delimiter.
D. Spaces: Spaces can be used as delimiters as well. If your data is separated by spaces, you can configure the Field Extractor to recognize spaces as delimiters.
So, all of the options (A, B, C, D) can work as delimiters when using the Field Extractor in Splunk, depending on how your data is structured and separated. You can choose the appropriate delimiter that matches the format of your data.
So all the Splunk docs say " comma and space for sure" but the document reference below does include colons and tabs. (You can use the DELIMS attribute in field transforms to configure field extractions for events where field values or field/value pairs are separated by delimiters such as commas, colons, tab spaces, and more.) = ABCD in my OP
ABCD is correct:When using the Field Extractor (FX) in Splunk, several delimiters can be used to extract fields from events, including:
Space ( ): Used to extract fields that are separated by spaces.
Comma (,): Used to extract fields that are separated by commas.
Tab (\t): Used to extract fields that are separated by tabs.
Pipe (|): Used to extract fields that are separated by pipes.
Semi-colon (;): Used to extract fields that are separated by semi-colons.
ABCD
You can use the DELIMS attribute in field transforms to configure field extractions for events where field values or field/value pairs are separated by delimiters such as commas, colons, tab spaces, and more.
https://docs.splunk.com/Documentation/Splunk/9.0.4/Knowledge/Exampleconfigurationsusingfieldtransforms
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
TeeCeeP
Highly Voted 4 years agogcalcaterra
3 years, 11 months agoantukin
3 years, 9 months agoMxQ3
2 years, 5 months agosainfosec
Highly Voted 3 years, 5 months agoassfedassfinished
Most Recent 3 weeks, 2 days agodarNiz
9 months, 2 weeks agoANki_24
10 months, 3 weeks agoSankardevarajan1986
11 months, 3 weeks agojimil001
11 months, 3 weeks agoexampass999
1 year, 2 months agokruasan
1 year, 2 months agoHuslayer
1 year, 4 months agon00r1
1 year, 5 months agoMntman77
1 year, 5 months agoHarrysa
1 year, 7 months agomohanmk95
1 year, 8 months agotomhola
1 year, 8 months agometromini
1 year, 11 months agofodder137
1 year, 12 months ago