<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field extraction failing in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423975#M6287</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have input data that has a field named "tag" and Splunk is not extracting this field correctly. Any suggestions are appreciated! &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6932i0F03D6D27EE8F4E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2019 17:48:58 GMT</pubDate>
    <dc:creator>grantccarlson</dc:creator>
    <dc:date>2019-04-23T17:48:58Z</dc:date>
    <item>
      <title>Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423975#M6287</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have input data that has a field named "tag" and Splunk is not extracting this field correctly. Any suggestions are appreciated! &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6932i0F03D6D27EE8F4E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 17:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423975#M6287</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-23T17:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423976#M6288</link>
      <description>&lt;P&gt;Which column of your csv data is field tag?? Could you share your configuration for field extraction (or sourcetype parsing)?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 18:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423976#M6288</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-04-23T18:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423977#M6289</link>
      <description>&lt;P&gt;The "tag" field is the last field in the data. &lt;/P&gt;

&lt;P&gt;Time,src_user,recipient,subject,file_name,tag&lt;BR /&gt;
4/1/19 10:00,Ty,George,Memo,Virus,email&lt;BR /&gt;
4/2/19 10:00,George,James,Please see!, ,email&lt;BR /&gt;
4/3/19 10:00,Mark,Josephine Daakjy,Memo,Memo,email&lt;/P&gt;

&lt;P&gt;Here are the first 3 rows of the data. I have removed last names to make the data anonymous.  &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:13:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423977#M6289</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2020-09-30T00:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423978#M6290</link>
      <description>&lt;P&gt;What's the sourcetype that you've assigned to this sourcetype? Have you configured anything for the &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/7.2.4/Data/Extractfieldsfromfileswithstructureddata"&gt;CSV field extraction&lt;/A&gt;? &lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 19:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423978#M6290</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-04-23T19:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423979#M6291</link>
      <description>&lt;P&gt;The source type is CSV. I did go through the field extractions -&amp;gt; delimiter to try to rename and extract all the fields. So far I am not having any luck with that process either. &lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 19:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423979#M6291</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-23T19:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423980#M6292</link>
      <description>&lt;P&gt;I also tried to extract the fields via the "+Extract New Fields" option at the bottom on the fields list in the UI, but this also does not work. &lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 20:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423980#M6292</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-23T20:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423981#M6293</link>
      <description>&lt;P&gt;I suggest you update your post with WAAAAAAAAAAAAAAAAAAAAAY more detail.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 01:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423981#M6293</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-24T01:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423982#M6294</link>
      <description>&lt;P&gt;What sort of detail do you need? &lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 02:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423982#M6294</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-24T02:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423983#M6295</link>
      <description>&lt;P&gt;A complete do-over.  What is your search SPL?  What is your expected output?  If your data &lt;CODE&gt;has a field named "tag"&lt;/CODE&gt;, then why do I not see any evidence of this (I guess this is what you are saying is the problem)?  What is the field extraction (from props.conf) that is supposed to create this field?  Where in one of your sample raw events is the portion of the event that makes up the value for its &lt;CODE&gt;tag&lt;/CODE&gt; field.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 06:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423983#M6295</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-24T06:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction failing</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423984#M6296</link>
      <description>&lt;P&gt;You are likely going to run into an issue of having a "reserved" field name like tag, eventtype etc. where the extracted field tag is possibly going to be confused with Splunk tags. The suggestion would be to rename field at the source csv or have an explicit field extraction to help you.&lt;/P&gt;

&lt;P&gt;This might help : &lt;A href="https://answers.splunk.com/answers/659101/is-there-a-list-of-unusable-field-names.html"&gt;https://answers.splunk.com/answers/659101/is-there-a-list-of-unusable-field-names.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 07:52:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-failing/m-p/423984#M6296</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2019-04-24T07:52:54Z</dc:date>
    </item>
  </channel>
</rss>

