<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Extract the field from raw data in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550333#M37998</link>
    <description>&lt;P&gt;Use rex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "message=(?&amp;lt;messageTime&amp;gt;\d+-\d+-\d+\s\d+:\d+:\d+\.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;but depending on how you have set up your ingestion, it's likely that Splunk is already finding the event time field from the timestamp of the event at the start of the raw data. Is that always the same. If so, you can use just _time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 06:38:50 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2021-05-04T06:38:50Z</dc:date>
    <item>
      <title>How to Extract the field from raw data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550332#M37997</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;Can someone guide me how to extract the filed from raw data.(The field highlighted in bold)&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2021-05-03T20:34:46.574469127Z&lt;/SPAN&gt; &lt;SPAN class="t"&gt;app_name=blazegqlgway-a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;environment=e2&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ns=blazegateway&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pod_container=blazegqlgway-a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pod_name=blazegqlgway-a-deployment-11-5sk6b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;stream=stdout&lt;/SPAN&gt; &lt;SPAN class="t"&gt;message=&lt;STRONG&gt;2021-05-03&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt; &lt;SPAN class="t"&gt;13:34:46.574&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;dgfgateway&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;c6e3e9be5ff5499a&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;c6e3e9be5ff5499a&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;true&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;nio-8443-exec-7&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;c.a.s.g.s.h.ResponseRetrieverService&lt;/SPAN&gt; &lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;nodeUrl=https://abc/graphql&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;caller=200000949GCPSfdcCommerical&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;nodeHttpStatus=200&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;nodeResponseTime=691&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2021-05-03T10:04:33.485822671Z app_name=blazegqlgway-a environment=e2 ns=blazegateway pod_container=blazegqlgway-a pod_name=blazegqlgway-a-deployment-11-5sk6b stream=stdout message=&lt;STRONG&gt;2021-05-03 03:04:33.485&lt;/STRONG&gt; INFO&lt;SPAN&gt; [&lt;/SPAN&gt;dgfgateway&lt;SPAN&gt;,&lt;/SPAN&gt;68cdbc43702536b4&lt;SPAN&gt;,&lt;/SPAN&gt;68cdbc43702536b4&lt;SPAN&gt;,&lt;/SPAN&gt;true&lt;SPAN&gt;] &lt;/SPAN&gt;1&lt;SPAN&gt; --&lt;/SPAN&gt;-&lt;SPAN&gt; [&lt;/SPAN&gt;nio-8443-exec-7&lt;SPAN&gt;] &lt;/SPAN&gt;c.a.s.g.s.h.ResponseRetrieverService : nodeUrl=https://jkl/graphql&lt;SPAN&gt;, &lt;/SPAN&gt;caller=200000949GCPSfdcCommerical&lt;SPAN&gt;, &lt;/SPAN&gt;nodeHttpStatus=200&lt;SPAN&gt;, &lt;/SPAN&gt;nodeResponseTime=615&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 06:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550332#M37997</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-05-04T06:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to Extract the field from raw data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550333#M37998</link>
      <description>&lt;P&gt;Use rex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "message=(?&amp;lt;messageTime&amp;gt;\d+-\d+-\d+\s\d+:\d+:\d+\.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;but depending on how you have set up your ingestion, it's likely that Splunk is already finding the event time field from the timestamp of the event at the start of the raw data. Is that always the same. If so, you can use just _time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 06:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550333#M37998</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-04T06:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to Extract the field from raw data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550335#M37999</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in this case I suggest to use the extract key-value extraction&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Knowledge/Automatickey-valuefieldextractionsatsearch-time" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Knowledge/Automatickey-valuefieldextractionsatsearch-time&lt;/A&gt;&lt;/P&gt;&lt;P&gt;most of your log is managed like this&lt;/P&gt;&lt;P&gt;key="value" key2="value"&lt;/P&gt;&lt;P&gt;in this case you can set this on your props.conf under the sourcetype stanza&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;KV_MODE = auto&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 04 May 2021 06:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-Extract-the-field-from-raw-data/m-p/550335#M37999</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-04T06:56:43Z</dc:date>
    </item>
  </channel>
</rss>

