<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: error while trying to extracting fields using regex in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618485#M106718</link>
    <description>&lt;P&gt;It's hard to optimize the regex with such a small sample size. But you can try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;^[^\s]*\s(?&amp;lt;ip_address&amp;gt;\d+\.\d+\.\d+\.\d+)\s(?&amp;lt;status_code&amp;gt;[^\|]*)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 22:06:07 GMT</pubDate>
    <dc:creator>johnhuang</dc:creator>
    <dc:date>2022-10-26T22:06:07Z</dc:date>
    <item>
      <title>Receiving error while trying to extracting fields using regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618484#M106717</link>
      <description>&lt;P&gt;Hi Splunkers&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to extract some fields using the opting under the log "&lt;SPAN&gt;Extract Fields&lt;/SPAN&gt;" using the regix method.&lt;/P&gt;
&lt;P&gt;In the step of "Select Fields" when I select a filed that I would like to extract, it freezes for a couple of minutes and returns with the following message:&lt;/P&gt;
&lt;P&gt;"The extraction failed. If you are extracting multiple fields, try removing one or more fields. Start with extractions that are embedded within longer text strings."&lt;/P&gt;
&lt;P&gt;So I'm not "extracting multiple fields", its just one filed, and yet the error still appears.&lt;/P&gt;
&lt;P&gt;Here is the log sample I used:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2022-10-26T20:10:11+03:00 192.168.xxx.xxx&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TRP&lt;/SPAN&gt;&lt;SPAN&gt;|No Caller ID received: Line: 8 Slot: 2 Port: 12&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I was just trying to extract the "TRP".&lt;/P&gt;
&lt;P&gt;I have tried different ways to solve this issue:&lt;/P&gt;
&lt;P&gt;I have tried the "I prefer to write the regular expression myself" option in the "Select Method" step and entered the regix and hit "Preview" but it just stuck.&lt;/P&gt;
&lt;P&gt;I have tried to use other log sample with no luck.&lt;/P&gt;
&lt;P&gt;Tried using totally different log from a totally&amp;nbsp;different index but ended up with the same error message.&lt;/P&gt;
&lt;P&gt;Even restated Splunk but no luck either!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What am I missing here?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 22:27:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618484#M106717</guid>
      <dc:creator>muradgh</dc:creator>
      <dc:date>2022-10-26T22:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: error while trying to extracting fields using regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618485#M106718</link>
      <description>&lt;P&gt;It's hard to optimize the regex with such a small sample size. But you can try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;^[^\s]*\s(?&amp;lt;ip_address&amp;gt;\d+\.\d+\.\d+\.\d+)\s(?&amp;lt;status_code&amp;gt;[^\|]*)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 22:06:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618485#M106718</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-26T22:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: error while trying to extracting fields using regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618532#M106724</link>
      <description>&lt;P&gt;I don't have a problem with the regex itself, whatever field I select or regex I provide, it shows the same error&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 06:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Receiving-error-while-trying-to-extracting-fields-using-regex/m-p/618532#M106724</guid>
      <dc:creator>muradgh</dc:creator>
      <dc:date>2022-10-27T06:57:29Z</dc:date>
    </item>
  </channel>
</rss>

