<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field extractions are incomplete for juniper in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491134#M60473</link>
    <description>&lt;P&gt;The log is not complete when viewing these weird extractions&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 26 Nov 2019 08:13:29 GMT</pubDate>
    <dc:creator>nathanluke86</dc:creator>
    <dc:date>2019-11-26T08:13:29Z</dc:date>
    <item>
      <title>Field extractions are incomplete for juniper</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491130#M60469</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are extracting juniper logs using the Juniper addon and are getting random fields as pictured.&lt;/P&gt;

&lt;P&gt;Could someone explain why this might be happening&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7985i90D02BCD962F7B47/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 09:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491130#M60469</guid>
      <dc:creator>nathanluke86</dc:creator>
      <dc:date>2019-11-19T09:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Field extractions are incomplete for juniper</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491131#M60470</link>
      <description>&lt;P&gt;Hi @nathanluke86,&lt;/P&gt;

&lt;P&gt;Are you on a distributed env ? If so where have you installed the ad-on ?&lt;/P&gt;

&lt;P&gt;Search time components of the TA should go on the search head to get the cleanest extractions possible.&lt;/P&gt;

&lt;P&gt;In your case it seems that the auto-extractions are grabbing lots of weird fields and polluting your field list. In order to disable it modify your local &lt;CODE&gt;props.conf&lt;/CODE&gt; to include &lt;CODE&gt;KV_MODE = none&lt;/CODE&gt; that way auto-extraction will be disabled.&lt;/P&gt;

&lt;P&gt;More info here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/Knowledge/Automatickey-valuefieldextractionsatsearch-time#Automatic_key-value_field_extraction_format"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/Knowledge/Automatickey-valuefieldextractionsatsearch-time#Automatic_key-value_field_extraction_format&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 09:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491131#M60470</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-11-19T09:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Field extractions are incomplete for juniper</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491132#M60471</link>
      <description>&lt;P&gt;Hi @DavidHourani &lt;/P&gt;

&lt;P&gt;We are in a distributed env. I have checked props.conf and KV_MODE is set to none. The TA is installed on all forwarders and Search heads.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 10:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491132#M60471</guid>
      <dc:creator>nathanluke86</dc:creator>
      <dc:date>2019-11-20T10:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Field extractions are incomplete for juniper</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491133#M60472</link>
      <description>&lt;P&gt;Are those fields showing over all time ? Click on one of the weird fields and check what the event looks like, wether its broken or not.&lt;/P&gt;

&lt;P&gt;Also check if there are other places where the sourcetype might be grabbing its config from use &lt;CODE&gt;btool&lt;/CODE&gt; to verify that.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 10:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491133#M60472</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-11-20T10:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Field extractions are incomplete for juniper</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491134#M60473</link>
      <description>&lt;P&gt;The log is not complete when viewing these weird extractions&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 08:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Field-extractions-are-incomplete-for-juniper/m-p/491134#M60473</guid>
      <dc:creator>nathanluke86</dc:creator>
      <dc:date>2019-11-26T08:13:29Z</dc:date>
    </item>
  </channel>
</rss>

