eg. search `set_sos_index` host="SPLUNK1.EDM.LOCAL" sourcetype="lsof"\n | head 1\n | multikv \n | `get_splunk_process_type_lsof`