<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help getting field extraction from information in field=source in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598447#M104394</link>
    <description>&lt;P&gt;Hi&amp;nbsp;@VatsalJagan&amp;nbsp; I would like to do it during indexing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do that via props.conf and transforms.conf.&lt;/P&gt;&lt;P&gt;Are you able to show me that props and transforms configurations.&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2022 08:21:40 GMT</pubDate>
    <dc:creator>harry17preet</dc:creator>
    <dc:date>2022-05-19T08:21:40Z</dc:date>
    <item>
      <title>Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598395#M104386</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am ingesting some logs from Heavy Forwarder and then sending them to indexers.&lt;/P&gt;
&lt;P&gt;*Snippet from inputs.conf on the Universal Forwarder&lt;/P&gt;
&lt;P&gt;[monitor:///opt/splunk/etc/apps/nonprod_apicalls/local/ce_p2_srv_data2_env_getstats_port.txt]&lt;/P&gt;
&lt;P&gt;disabled = false&lt;/P&gt;
&lt;P&gt;sourcetype = my:api:ce2&lt;/P&gt;
&lt;P&gt;index = internet&lt;/P&gt;
&lt;P&gt;I would like to extract "data2" text from the filename.&amp;nbsp; I did a rex field extraction on search head and it works giving me "instance" field name under interesting fields on Search UI. Below is the regex I used&lt;/P&gt;
&lt;P&gt;| rex field=source "\/(.+\/)(?:[^_]+_[^_]+_[^_]+_)(?&amp;lt;instance&amp;gt;[^_]+)"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So next step I did is created props.conf with below configuration&lt;/P&gt;
&lt;P&gt;[my:api:ce2]&lt;BR /&gt;EXTRACT-instance = \/(.+\/)(?:[^_]+_[^_]+_[^_]+_)(?&amp;lt;instance&amp;gt;[^_]+) in source&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Restarted the splunk service on Heavy Forwarder, but it doesn't work.&lt;/P&gt;
&lt;P&gt;Can someone advise me if I am doing something wrong here or what is the issue.&lt;/P&gt;
&lt;P&gt;Thankyou&lt;/P&gt;
&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 02:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598395#M104386</guid>
      <dc:creator>harry17preet</dc:creator>
      <dc:date>2022-05-19T02:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598417#M104388</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if you want to do that on search time you must add this extractions to SH's props.conf in some application. My proposal is to create your own app where put these, not in search app! &amp;nbsp;See:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/What-kind-of-things-do-you-view-as-quot-bad-config-quot/m-p/594893#M12359" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/What-kind-of-things-do-you-view-as-quot-bad-config-quot/m-p/594893#M12359&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you want to do this on ingest time and create a indexed field (probably not worth of it?) then you must use props.conf + transforms.conf on HF. I'm expecting that you need this a search time not on ingesting time + indexed field?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 05:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598417#M104388</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-05-19T05:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598424#M104389</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245971"&gt;@harry17preet&lt;/a&gt;&amp;nbsp;-&amp;nbsp;&lt;SPAN&gt;EXTRACT is a search-time parameter. You need to add on the Search Head and not on HF.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 06:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598424#M104389</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-19T06:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598447#M104394</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@VatsalJagan&amp;nbsp; I would like to do it during indexing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do that via props.conf and transforms.conf.&lt;/P&gt;&lt;P&gt;Are you able to show me that props and transforms configurations.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 08:21:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598447#M104394</guid>
      <dc:creator>harry17preet</dc:creator>
      <dc:date>2022-05-19T08:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598448#M104395</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; I would like to do it during indexing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do that via props.conf and transforms.conf.&lt;/P&gt;&lt;P&gt;Are you able to show me the props and transforms configurations.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 08:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598448#M104395</guid>
      <dc:creator>harry17preet</dc:creator>
      <dc:date>2022-05-19T08:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598453#M104396</link>
      <description>&lt;P&gt;Here is quite similar case&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Index-time-field-extractions-path/m-p/241831" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Index-time-field-extractions-path/m-p/241831&lt;/A&gt;. Probably you can do it based on that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 09:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598453#M104396</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-05-19T09:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598456#M104398</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245971"&gt;@harry17preet&lt;/a&gt;&amp;nbsp;-&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf (HF)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[my:api:ce2]
TRANSFORMS-extract_instance = extract_instance&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;transforms.conf (HF)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[extract_instance]
SOURCE_KEY = MetaData:Source
REGEX = \/(.+\/)(?:[^_]+_[^_]+_[^_]+_)(?&amp;lt;instance&amp;gt;[^_]+)
WRITE_META = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fields.conf (SH)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[instance]
INDEXED = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note you have to deploy props.conf and transforms.conf at HF (indexing level) and fields.conf on SH.&lt;/P&gt;&lt;P&gt;Also, not that at index time source value (MetaData:Source) will be prefixed by "source::", but I think your regex will still work, but please confirm on your end.&lt;/P&gt;&lt;P&gt;(Reference/Doc -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/transformsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/transformsconf&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Karma/upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 09:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598456#M104398</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-19T09:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598590#M104412</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;, thanks heaps. that works.&lt;/P&gt;&lt;P&gt;Are you also able to provide me details on search time extraction.&amp;nbsp; Same details only change change is source file name will vary like :&amp;nbsp;/opt/splunk/etc/apps/ce/local/app/ce_*_data2_*_*.txt.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 01:11:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598590#M104412</guid>
      <dc:creator>harry17preet</dc:creator>
      <dc:date>2022-05-20T01:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help getting field extraction from information in field=source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598597#M104413</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245971"&gt;@harry17preet&lt;/a&gt;&amp;nbsp;- As you requested this is index-time.&lt;/P&gt;&lt;P&gt;You can search the index time field like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=&amp;lt;your-index&amp;gt; instance::myinstance &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For search-time extraction, you can use the EXTRACT that I mentioned in my previous answer.&amp;nbsp; Search-time extracted field you can search with regular syntax (instance="myinstance").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 04:05:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-getting-field-extraction-from-information-in-field-source/m-p/598597#M104413</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-20T04:05:22Z</dc:date>
    </item>
  </channel>
</rss>

