<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk 6 auto key value extraction not working? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-6-auto-key-value-extraction-not-working/m-p/99279#M20769</link>
    <description>&lt;P&gt;I have recently installed splunk 6, almost certain this worked fine in splunk 5...&lt;/P&gt;

&lt;P&gt;I have extracted a number of fields from one index into another using the "| collect index=events" function. Now I have the fields in the new index and the raw data contains the key values i expected, but they are not being auto extracted by splunk?&lt;/P&gt;

&lt;P&gt;I have also tested this with some other data which also doesn't extract, and turned on verbose mode.&lt;/P&gt;

&lt;P&gt;Example data:&lt;/P&gt;

&lt;P&gt;time="2013/06/06 15:15:15" data="test" seconddata="test2"&lt;/P&gt;

&lt;P&gt;05/09/2013 23:45:39 +0100, info_search_time=1381837886.531, bytes=214, client_ip="192.168.0.1", company=test1, destination_ip="10.0.0.1", domain="example.com", method=GET, reason="Not Found", status=404, uri="/test-env"&lt;/P&gt;

&lt;P&gt;Question: Is there some global setting to turn on KV extraction? Otherwise is it something I have broken?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 14:58:19 GMT</pubDate>
    <dc:creator>mmmmssss</dc:creator>
    <dc:date>2020-09-28T14:58:19Z</dc:date>
    <item>
      <title>Splunk 6 auto key value extraction not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-6-auto-key-value-extraction-not-working/m-p/99279#M20769</link>
      <description>&lt;P&gt;I have recently installed splunk 6, almost certain this worked fine in splunk 5...&lt;/P&gt;

&lt;P&gt;I have extracted a number of fields from one index into another using the "| collect index=events" function. Now I have the fields in the new index and the raw data contains the key values i expected, but they are not being auto extracted by splunk?&lt;/P&gt;

&lt;P&gt;I have also tested this with some other data which also doesn't extract, and turned on verbose mode.&lt;/P&gt;

&lt;P&gt;Example data:&lt;/P&gt;

&lt;P&gt;time="2013/06/06 15:15:15" data="test" seconddata="test2"&lt;/P&gt;

&lt;P&gt;05/09/2013 23:45:39 +0100, info_search_time=1381837886.531, bytes=214, client_ip="192.168.0.1", company=test1, destination_ip="10.0.0.1", domain="example.com", method=GET, reason="Not Found", status=404, uri="/test-env"&lt;/P&gt;

&lt;P&gt;Question: Is there some global setting to turn on KV extraction? Otherwise is it something I have broken?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-6-auto-key-value-extraction-not-working/m-p/99279#M20769</guid>
      <dc:creator>mmmmssss</dc:creator>
      <dc:date>2020-09-28T14:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6 auto key value extraction not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-6-auto-key-value-extraction-not-working/m-p/99280#M20770</link>
      <description>&lt;P&gt;I see the same behavior when I tried looking at one of the S.O.S dashboards after upgrading to Splunk 6. While some fields (searchid etc) are auto extracted. The total_run_time, event_count are not.&lt;/P&gt;

&lt;P&gt;5/9/14 &lt;BR /&gt;
2:16:53.552 PM&lt;BR /&gt;&lt;BR /&gt;
Audit:[timestamp=05-09-2014 14:16:53.552, user=splunk, action=search, info=canceled, search_id='1399670142.1517.xyz', total_run_time=2.75, event_count=0, result_count=0, available_count=0, scan_count=0, drop_count=0, exec_time=1399670142, api_et=1397026800.000000000, api_lt=1399670142.000000000, search_et=1397026800.000000000, search_lt=1399670142.000000000, is_realtime=0, savedsearch_name=""][n/a]&lt;BR /&gt;
5/9/14 &lt;BR /&gt;
2:15:42.334 PM&lt;BR /&gt;&lt;BR /&gt;
Audit:[timestamp=05-09-2014 14:15:42.334, user=splunk, action=search, info=granted , search_id='1399670142.1517.xyz', search='search index=splunk', autojoin='1', buckets=300, ttl=600, max_count=10000, maxtime=8640000, enable_lookups='1', extra_fields='*', apiStartTime='Wed Apr  9 00:00:00 2014', apiEndTime='Fri May  9 14:15:42 2014', savedsearch_name=""][n/a]&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-6-auto-key-value-extraction-not-working/m-p/99280#M20770</guid>
      <dc:creator>tupadhyaya</dc:creator>
      <dc:date>2020-09-28T16:37:00Z</dc:date>
    </item>
  </channel>
</rss>

