<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field extraction from alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/503713#M9066</link>
    <description>&lt;P&gt;Hi. I have a task to extract all fields from raw logs used by our alerts and I wonder if there is an automated way to do it, or I have to go manually through each alert to check what fields are used? All help is really appreciated&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2020 12:55:26 GMT</pubDate>
    <dc:creator>DawidM</dc:creator>
    <dc:date>2020-06-10T12:55:26Z</dc:date>
    <item>
      <title>Field extraction from alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/503713#M9066</link>
      <description>&lt;P&gt;Hi. I have a task to extract all fields from raw logs used by our alerts and I wonder if there is an automated way to do it, or I have to go manually through each alert to check what fields are used? All help is really appreciated&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 12:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/503713#M9066</guid>
      <dc:creator>DawidM</dc:creator>
      <dc:date>2020-06-10T12:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/503725#M9067</link>
      <description>&lt;P&gt;It depends.&amp;nbsp; What tool is producing the alerts?&amp;nbsp; In what format are they?&lt;/P&gt;&lt;P&gt;Splunk will automatically extract fields in key=value format.&amp;nbsp; Other formats are supported if the correct sourcetype is specified, but we need more information.&amp;nbsp; Can you share some sample alerts (sanitized, of course)?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 12:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/503725#M9067</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-10T12:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/504430#M9075</link>
      <description>&lt;P&gt;We have logs from firewalls and web applications. What I need is to extract field names that are used by our alerts (queries) to compare the, with the fields used by a different team and tools.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 13:27:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/504430#M9075</guid>
      <dc:creator>DawidM</dc:creator>
      <dc:date>2020-06-15T13:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/504437#M9076</link>
      <description>Check splunkbase (&lt;A href="https://apps.splunk.com" target="_blank"&gt;https://apps.splunk.com&lt;/A&gt;) for add-ons that will help you ingest the data from your firewalls and applications. Changes are they comply with the Common Information Model so the field names are well-known.</description>
      <pubDate>Mon, 15 Jun 2020 14:01:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Field-extraction-from-alerts/m-p/504437#M9076</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-15T14:01:01Z</dc:date>
    </item>
  </channel>
</rss>

