<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I create extractions where it can pick field names from the events See events below in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553441#M91758</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/142528"&gt;@puneetkharband1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;expand your event and select event actions &amp;gt; extract fields&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_0-1622181336243.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14350i6C9301C41D5405EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_0-1622181336243.png" alt="aasabatini_0-1622181336243.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;it's will open another page like this, please select delimiters and click next&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_1-1622181445975.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14351i0F7AA61D0E7ADB94/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_1-1622181445975.png" alt="aasabatini_1-1622181445975.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;here select the delimiters other and insert ":" and&amp;nbsp; modify your name fields&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_2-1622181599585.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14352iDDEF21132C01724D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_2-1622181599585.png" alt="aasabatini_2-1622181599585.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 May 2021 06:00:56 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-05-28T06:00:56Z</dc:date>
    <item>
      <title>How do I create extractions where it can pick field names from the events See events below</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553430#M91757</link>
      <description>&lt;P&gt;I have 2 types of logs from one source where I need to map fields vs values ...I dont want to create complex regex as they are from structured data so how do I create fields and values from events&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;May 27 07:51:49 TESTHOSTTEST TESTDEVTEST_11.2.0.125: User '' (root) : FAILED: Sign On, ID: 123220127, InstID: 7653, IPAddress: 111.222.213.238, FolderID: 0, Username: root, AgentBrand: TEST DEV SSH, AgentVersion: 11.2.0.0, DEVSize: 0, Error: 2976, Message: Failed to sign on: This IP address has been locked out.&lt;BR /&gt;&lt;BR /&gt;May 27 07:51:34 TESTHOSTTEST TESTDEVTEST_11.2.0.125: User 'BLA BLA DI' (ei4o2f18pcsuo5tp) : Download File, ID: 123220102, InstID: 7653, IPAddress: 333.222.231.94, FileID: 770879833, FileName: 16680_Signup Detail_20210527 01-49-18-86.csv, FolderID: 472070079, FolderPath: /Home/test/TestWorks/Enhanced Affiliate Signup Reports, Username: TEST, AgentBrand: Chrome Browser, AgentVersion: 90.0.4430.212, DEVSize: 739698, Parm2: 0, Error: 0&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 03:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553430#M91757</guid>
      <dc:creator>puneetkharband1</dc:creator>
      <dc:date>2021-05-28T03:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create extractions where it can pick field names from the events See events below</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553441#M91758</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/142528"&gt;@puneetkharband1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;expand your event and select event actions &amp;gt; extract fields&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_0-1622181336243.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14350i6C9301C41D5405EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_0-1622181336243.png" alt="aasabatini_0-1622181336243.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;it's will open another page like this, please select delimiters and click next&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_1-1622181445975.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14351i0F7AA61D0E7ADB94/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_1-1622181445975.png" alt="aasabatini_1-1622181445975.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;here select the delimiters other and insert ":" and&amp;nbsp; modify your name fields&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_2-1622181599585.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14352iDDEF21132C01724D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_2-1622181599585.png" alt="aasabatini_2-1622181599585.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 06:00:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553441#M91758</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-28T06:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create extractions where it can pick field names from the events See events below</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553502#M91770</link>
      <description>&lt;P&gt;this doesnt work I tried delimiter option.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 12:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553502#M91770</guid>
      <dc:creator>puneetkharband1</dc:creator>
      <dc:date>2021-05-28T12:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create extractions where it can pick field names from the events See events below</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553506#M91771</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/142528"&gt;@puneetkharband1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are your sure that logs are structured data?, like as you shared looks like not structured, anyway&amp;nbsp; if are not structured you need to use mandatory the regular expression.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 13:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553506#M91771</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-28T13:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create extractions where it can pick field names from the events See events below</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553533#M91774</link>
      <description>&lt;P&gt;if you see there is one pattern and these logs are generated from a tool(Xfer) and only 2 types of logs are there which I posted.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 14:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-create-extractions-where-it-can-pick-field-names-from/m-p/553533#M91774</guid>
      <dc:creator>puneetkharband1</dc:creator>
      <dc:date>2021-05-28T14:31:05Z</dc:date>
    </item>
  </channel>
</rss>

