<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fields using regular expressions in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695628#M10210</link>
    <description>&lt;P&gt;I would like to automatically extract fields using props.conf.&lt;BR /&gt;When there is a pattern like the one below, what I want to extract is each file name. attach_filename:[""] contains one or two file names.&lt;BR /&gt;How can I extract all file names?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"attach_filename":["image.png","GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent"]
"attach_filename":["image.png","Office2016_Patcher_For_OSX.torrent"]
"attach_filename":["image.png"]
"attach_filename":["Saccharomyces_cerevisiae_patent.docx"]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;field extract will be store file_name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;file_name : image.png,&amp;nbsp;&lt;BR /&gt;Saccharomyces_cerevisiae_patent.docx,&amp;nbsp;&lt;BR /&gt;GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent,&amp;nbsp;Office2016_Patcher_For_OSX.torrent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2024 01:49:30 GMT</pubDate>
    <dc:creator>silverKi</dc:creator>
    <dc:date>2024-08-08T01:49:30Z</dc:date>
    <item>
      <title>Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695628#M10210</link>
      <description>&lt;P&gt;I would like to automatically extract fields using props.conf.&lt;BR /&gt;When there is a pattern like the one below, what I want to extract is each file name. attach_filename:[""] contains one or two file names.&lt;BR /&gt;How can I extract all file names?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"attach_filename":["image.png","GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent"]
"attach_filename":["image.png","Office2016_Patcher_For_OSX.torrent"]
"attach_filename":["image.png"]
"attach_filename":["Saccharomyces_cerevisiae_patent.docx"]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;field extract will be store file_name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;file_name : image.png,&amp;nbsp;&lt;BR /&gt;Saccharomyces_cerevisiae_patent.docx,&amp;nbsp;&lt;BR /&gt;GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent,&amp;nbsp;Office2016_Patcher_For_OSX.torrent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 01:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695628#M10210</guid>
      <dc:creator>silverKi</dc:creator>
      <dc:date>2024-08-08T01:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695637#M10211</link>
      <description>&lt;P&gt;My first reaction is: regex is the wrong solution. &amp;nbsp;This looks like part of a JSON document. &amp;nbsp;Treating structured data as text string is just calling for trouble down the road. &amp;nbsp;Can you share raw events? (Anonymize as needed.)&lt;/P&gt;&lt;P&gt;Or, if this is a developer's joke, and you only have this string in a field, let's call it field1, you can still use Splunk's JSON capability to extract data. &amp;nbsp;It's much more robust. &amp;nbsp;Something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval field1 = "{" . field1 . "}"
| spath input=field1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your mock data will give&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;attach_filename{}&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;field1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;image.png&lt;/DIV&gt;&lt;DIV class=""&gt;GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;{"attach_filename":["image.png","GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent"]}&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;image.png&lt;/DIV&gt;&lt;DIV class=""&gt;Office2016_Patcher_For_OSX.torrent&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;{"attach_filename":["image.png","Office2016_Patcher_For_OSX.torrent"]}&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;image.png&lt;/TD&gt;&lt;TD&gt;{"attach_filename":["image.png"]}&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Saccharomyces_cerevisiae_patent.docx&lt;/TD&gt;&lt;TD&gt;{"attach_filename":["Saccharomyces_cerevisiae_patent.docx"]}&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is an emulation you can play with and compare with real data, if your developers really play such a joke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _*
| eval field1 = split("\"attach_filename\":[\"image.png\",\"GoT.S7E2.BOTS.BOTS.BOTS.mkv.torrent\"]
\"attach_filename\":[\"image.png\",\"Office2016_Patcher_For_OSX.torrent\"]
\"attach_filename\":[\"image.png\"]
\"attach_filename\":[\"Saccharomyces_cerevisiae_patent.docx\"]", "
")
| mvexpand field1
``` data emulation ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 04:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695637#M10211</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-08T04:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695639#M10212</link>
      <description>&lt;P&gt;you're right. I am trying to extract fields from JSON-data.&lt;/P&gt;&lt;P&gt;I used botsv2 data, in "stream:smtp" sourcetype.&lt;BR /&gt;&lt;BR /&gt;This is my _raw data(I try to search index="botsv2" sourcetype="stream:smtp").&lt;BR /&gt;&lt;SPAN&gt;The _raw data result.&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;&lt;BR /&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;endtime&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2017-08-31T22:56:56.070751Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2017-08-31T22:56:56.070751Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;ack_packets_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ack_packets_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:72&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:72&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;capture_hostname&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;matar&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt_packets&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt_sum&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;data_packets_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;data_packets_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;dest_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;172.31.38.181&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;dest_mac&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;06:6A:51:FA:0A:B0&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;dest_port&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:25&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;duplicate_packets_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;duplicate_packets_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;flow_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;b6b9eb1b-e8e1-4cec-ab3c-f7223adc490a&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;greeting&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ip-172-31-38-181.us-west-2.compute.internal&lt;/SPAN&gt; &lt;SPAN class=""&gt;ESMTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;Postfix&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Ubuntu&lt;/SPAN&gt;&lt;SPAN&gt;)","&lt;/SPAN&gt;&lt;SPAN class=""&gt;missing_packets_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;missing_packets_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;network_interface&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;eth0&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;packets_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;packets_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;protocol_stack&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ip:tcp:smtp&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;reply_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;request_ack_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;request_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;response_ack_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:24624&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;response_code&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:220&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;response_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;sender_server&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ip-172-31-38-181.us-west-2.compute.internal&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;server_agent&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ESMTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;Postfix&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Ubuntu&lt;/SPAN&gt;&lt;SPAN&gt;)","&lt;/SPAN&gt;&lt;SPAN class=""&gt;server_response&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;220&lt;/SPAN&gt; &lt;SPAN class=""&gt;ip-172-31-38-181.us-west-2.compute.internal&lt;/SPAN&gt; &lt;SPAN class=""&gt;ESMTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;Postfix&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Ubuntu&lt;/SPAN&gt;&lt;SPAN&gt;)","&lt;/SPAN&gt;&lt;SPAN class=""&gt;server_rtt&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;server_rtt_packets&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;server_rtt_sum&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;src_ip&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;104.47.34.68&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;src_mac&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;06:E3:CC:18:AA:33&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;src_port&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:37952&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;time_taken&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;transport&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;tcp&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN class=""&gt;I have one more question. The raw data results I searched with index=botsv2 sourcetype="stream:smtp" and Why are the search results with index="botsv2" sourcetype="stream:smtp" attach_filename{}="*" different? The field I want to extract exists in the search results with index="botsv2" sourcetype="stream:smtp" attach_filename{}="*".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Search Try: index="botsv2" sourcetype="stream:smtp" attach_filename{}="*"&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;endtime&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2017-08-30T15:08:00.075698Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2017-08-30T15:07:59.774655Z&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;ack_packets_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;ack_packets_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:31&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;attach_disposition&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;attachment&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;attach_filename&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;Saccharomyces_cerevisiae_patent.docx&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;attach_size&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;142540&lt;/SPAN&gt;&lt;SPAN&gt;],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;attach_size_decoded&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;104162&lt;/SPAN&gt;&lt;SPAN&gt;],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;attach_transfer_encoding&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;base64&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;attach_type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;application/vnd.openxmlformats&lt;/SPAN&gt;-officedocument.wordprocessingml.document&lt;/SPAN&gt;&lt;SPAN&gt;"],"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:155976&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes_in&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:155939&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes_out&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:37&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;capture_hostname&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;matar&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt_packets&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;client_rtt_sum&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;content&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;["&lt;/SPAN&gt;&lt;SPAN class=""&gt;DKIM-Signature:&lt;/SPAN&gt; &lt;SPAN class=""&gt;v=1&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;a=rsa-sha256&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;c=relaxed/relaxed&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;SPAN class=""&gt;\r\n&lt;/SPAN&gt; &lt;SPAN class=""&gt;d=jacobsmythe111.onmicrosoft.com&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;s=selector1-froth-ly&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;SPAN class=""&gt;\r\n&lt;/SPAN&gt; &lt;SPAN class=""&gt;h=From:Date:Subject:Message-ID:Content-Type:MIME-Version&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 05:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695639#M10212</guid>
      <dc:creator>silverKi</dc:creator>
      <dc:date>2024-08-08T05:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695642#M10213</link>
      <description>&lt;P&gt;So, you already have attach_filename{} extracted by Splunk. &amp;nbsp;No need for extra work. &amp;nbsp;Is this correct?&lt;/P&gt;&lt;P&gt;To answer your question about two searches, when you add an additional filter, you SHOULD expect the result to change. &amp;nbsp;It is obvious that not all events have that attach_filename{} field populated. &amp;nbsp;If you do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="botsv2" sourcetype="stream:smtp" attach_filename{}="*"&lt;/LI-CODE&gt;&lt;P&gt;you only select those events with this field. &amp;nbsp;Without&amp;nbsp;attach_filename{}="*", you pick up every event, including those that do not have&amp;nbsp;attach_filename{}.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 05:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695642#M10213</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-08T05:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695644#M10214</link>
      <description>&lt;PRE&gt;&lt;SPAN class=""&gt;Then, how do I change the field name from attach_filename{} to file_name?&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 08 Aug 2024 05:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695644#M10214</guid>
      <dc:creator>silverKi</dc:creator>
      <dc:date>2024-08-08T05:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695653#M10217</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;SPAN&gt;Then, how do I change the field name from attach_filename{} to file_name?&lt;/SPAN&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rename" target="_blank" rel="noopener"&gt;&lt;BR /&gt;rename&lt;/A&gt;&amp;nbsp;is your friend.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename attach_filename{} as filename&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 07:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695653#M10217</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-08T07:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695659#M10218</link>
      <description>&lt;P&gt;You can change the field name with the "rename" method,&lt;BR /&gt;but what I wanted was for the desired field name to be searched&lt;BR /&gt;when I searched with just&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=botsv2 sourcetype="stream:smtp"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;index=botsv2 sourcetype="stream:smtp" attach_filename{}="*" &lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;(Before,, In order to extraact file_name, I had to search for&amp;nbsp; that..)&lt;BR /&gt;&lt;BR /&gt;I took a hint from your words and solved it in a different way.&lt;BR /&gt;&lt;BR /&gt;Taking a hint that &lt;STRONG&gt;attach_filename{} was already extracted from splunk&lt;/STRONG&gt;,&lt;BR /&gt;I created a lookup-file using "spath" and made it "Auto-Lookup".&lt;BR /&gt;&lt;BR /&gt;Then, the field is now extracted and displayed with just index=botsv2 sourcetype="stream:smtp".&lt;BR /&gt;&lt;BR /&gt;I really appreciate your help. Thank You &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 07:50:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695659#M10218</guid>
      <dc:creator>silverKi</dc:creator>
      <dc:date>2024-08-08T07:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Fields using regular expressions</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695738#M10222</link>
      <description>&lt;P&gt;You know there is a field alias feature in Splunk, too. &amp;nbsp;That is a more appropriate solution if you do really want to search by a different name. &amp;nbsp;An extra lookup is clunky and also a compute cost.&lt;/P&gt;&lt;P&gt;Go to Settings -&amp;gt; Fields -&amp;gt; Field aliases. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 17:54:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Fields-using-regular-expressions/m-p/695738#M10222</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-08T17:54:44Z</dc:date>
    </item>
  </channel>
</rss>

