<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field Extractions for IAS app in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37178#M1674</link>
    <description>&lt;P&gt;Since I don't see much documentation for this app, what needs to be set in order for the lookups to happen?  Do I need to change sourcetype, source?&lt;/P&gt;</description>
    <pubDate>Thu, 26 Apr 2012 14:59:54 GMT</pubDate>
    <dc:creator>gregwilliams</dc:creator>
    <dc:date>2012-04-26T14:59:54Z</dc:date>
    <item>
      <title>Field Extractions for IAS app</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37178#M1674</link>
      <description>&lt;P&gt;Since I don't see much documentation for this app, what needs to be set in order for the lookups to happen?  Do I need to change sourcetype, source?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 14:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37178#M1674</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-04-26T14:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions for IAS app</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37179#M1675</link>
      <description>&lt;P&gt;Did you go through this below. It has the details that you need to create a lookup.  &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/User/Fieldlookupstutorial"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/User/Fieldlookupstutorial&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 15:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37179#M1675</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-04-26T15:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions for IAS app</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37180#M1676</link>
      <description>&lt;P&gt;The main thing is to make sure your sourcetype is set to &lt;CODE&gt;ias&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 23:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37180#M1676</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2012-04-26T23:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions for IAS app</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37181#M1677</link>
      <description>&lt;P&gt;got it.  I still see default logs however.  Do I need to put something else in my search string except for sourcetype=ias?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 14:43:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37181#M1677</guid>
      <dc:creator>gregwilliams</dc:creator>
      <dc:date>2012-04-27T14:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions for IAS app</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37182#M1678</link>
      <description>&lt;P&gt;Not sure I follow. Are you expecting to see a difference in the log entries themselves?  The lookup values appear as new extracted fields, so you should start to see them in the field picker at the left. You might need to click &lt;CODE&gt;pick fields&lt;/CODE&gt; to bring up the full list.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Apr 2012 00:11:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-Extractions-for-IAS-app/m-p/37182#M1678</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2012-04-28T00:11:27Z</dc:date>
    </item>
  </channel>
</rss>

