<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting a list of field extractions using the API in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380997#M68732</link>
    <description>&lt;P&gt;May I know in which screen you see 'Apply to' option?&lt;/P&gt;

&lt;P&gt;" I can only get an extraction in the list by setting the "Apply to" field to host from the dropdown in the UI"&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2019 07:51:49 GMT</pubDate>
    <dc:creator>jawaharas</dc:creator>
    <dc:date>2019-07-10T07:51:49Z</dc:date>
    <item>
      <title>Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380996#M68731</link>
      <description>&lt;P&gt;There are 2 endpoints that seem to return extractions which are data/transforms/extractions and data/props/extractions. I've created some extractions that don't appear in the list when I hit these endpoints. I can only get an extraction in the list by setting the "Apply to" field to host from the dropdown in the UI. Does anyone have any insight as to why the extraction has to be applied to a host for it to show up in endpoint output?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 15:11:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380996#M68731</guid>
      <dc:creator>joemaz95</dc:creator>
      <dc:date>2019-07-08T15:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380997#M68732</link>
      <description>&lt;P&gt;May I know in which screen you see 'Apply to' option?&lt;/P&gt;

&lt;P&gt;" I can only get an extraction in the list by setting the "Apply to" field to host from the dropdown in the UI"&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 07:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380997#M68732</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-07-10T07:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380998#M68733</link>
      <description>&lt;P&gt;Thanks for helping me clarify. The field in question is found here:&lt;BR /&gt;
Settings Dropdown &amp;gt; Fields &amp;gt; Field Extractions &amp;gt; New Field Extraction &amp;gt; Apply to _____ named _____&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 13:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380998#M68733</guid>
      <dc:creator>joemaz95</dc:creator>
      <dc:date>2019-07-10T13:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380999#M68734</link>
      <description>&lt;P&gt;Try these (it is probably in a different app that you think):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rest/servicesNS/-/-/data/transforms/extractions
|rest/servicesNS/-/-/data/props/extractions
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 23 Jul 2019 17:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/380999#M68734</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-23T17:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381000#M68735</link>
      <description>&lt;P&gt;Thanks for the response, this didn't appear to resolve the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 17:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381000#M68735</guid>
      <dc:creator>joemaz95</dc:creator>
      <dc:date>2019-08-22T17:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381001#M68736</link>
      <description>&lt;P&gt;The field extraction entity should be tagged (applied) to &lt;EM&gt;sourcetype, host or source&lt;/EM&gt;. It's required field. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="field extractions snapshot"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7302iA42967B1C1A798DA/image-size/large?v=v2&amp;amp;px=999" role="button" title="field extractions snapshot" alt="field extractions snapshot" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 05:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381001#M68736</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-08-26T05:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381002#M68737</link>
      <description>&lt;P&gt;Right! I'm trying to get a list of every field extraction, but only extractions tagged with "host" are returned.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 16:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381002#M68737</guid>
      <dc:creator>joemaz95</dc:creator>
      <dc:date>2019-08-26T16:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381003#M68738</link>
      <description>&lt;P&gt;It should be there. I tried to search an field extraction which is tagged to a sourcetype and the REST API returns result.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest /services/data/props/extractions
| search title="&amp;lt;NAME_OF_YOUR_FIELD_EXTRACTON&amp;gt;"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 27 Aug 2019 00:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381003#M68738</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-08-27T00:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381004#M68739</link>
      <description>&lt;P&gt;@joemaz95 &lt;BR /&gt;
Kindly accept the answer if it helped you.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 07:28:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381004#M68739</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-08-30T07:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381005#M68740</link>
      <description>&lt;P&gt;Unfortunately, the extractions in question still don't appear when hitting that endpoint.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 14:10:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381005#M68740</guid>
      <dc:creator>joemaz95</dc:creator>
      <dc:date>2019-08-30T14:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a list of field extractions using the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381006#M68741</link>
      <description>&lt;P&gt;How can anybody help you without more detail?  The answer that I provided absolutely works unless you do not have privilege/permission to access the endpoint, which is probably the case.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 22:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-a-list-of-field-extractions-using-the-API/m-p/381006#M68741</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-08-30T22:08:52Z</dc:date>
    </item>
  </channel>
</rss>

