<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Value in location field gets truncated when search is ran in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422553#M121335</link>
    <description>&lt;P&gt;Hi, I have not created any extraction it is happening automatically.&lt;BR /&gt;
Also, The issue is not happening with SINGAPORE (ABC) which also has a space in between&lt;/P&gt;</description>
    <pubDate>Fri, 02 Aug 2019 14:41:37 GMT</pubDate>
    <dc:creator>amahesh3</dc:creator>
    <dc:date>2019-08-02T14:41:37Z</dc:date>
    <item>
      <title>Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422549#M121331</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;In my Splunk logs, I have a field called location which stores values like" &lt;BR /&gt;
&lt;STRONG&gt;SINGAPORE (ABC)&lt;BR /&gt;
WASHINGTON DC (ABC)&lt;BR /&gt;
HONG KONG (ABC)&lt;BR /&gt;
NEW YORK (ABC)&lt;BR /&gt;
HO CHI MINH CITY VIETNAM (ABC)&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;But when I run a search  &lt;CODE&gt;|stats count&lt;/CODE&gt; by location the table which is displayed is: &lt;BR /&gt;
&lt;STRONG&gt;SINGAPORE (ABC)                500&lt;BR /&gt;
WASHINGTON                      300&lt;BR /&gt;
HONG                                    700&lt;BR /&gt;
NEW                                       600&lt;BR /&gt;
HO                                          300&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;As you can see every value except "SINGAPORE (ABC)" is automatically getting truncated as "HONG" or "NEW".&lt;BR /&gt;
This also has an impact on my dashboard visualization bar chart.&lt;/P&gt;

&lt;P&gt;But when I right-click on "NEW" and view events the logs which are displayed has the whole value "NEW YORK".&lt;/P&gt;

&lt;P&gt;I request your help in correcting this issue.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 11:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422549#M121331</guid>
      <dc:creator>amahesh3</dc:creator>
      <dc:date>2019-08-02T11:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422550#M121332</link>
      <description>&lt;P&gt;What are the props.conf settings for that sourcetype?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:35:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422550#M121332</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-02T12:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422551#M121333</link>
      <description>&lt;P&gt;Looks like the extraction is not accounting for spaces.  Is this an automatic extraction or is it something you created?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422551#M121333</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2019-08-02T12:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422552#M121334</link>
      <description>&lt;P&gt;Hello @amahesh3 ,&lt;/P&gt;

&lt;P&gt;Your field extraction is not created properly, because it does not appear to take into account locations with spaces in the name.  You need to provide an example of a some events with locations with spaces in the name, your current extraction configuration and then someone can assist with the proper replacement for the field extraction.&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 13:02:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422552#M121334</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-08-02T13:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422553#M121335</link>
      <description>&lt;P&gt;Hi, I have not created any extraction it is happening automatically.&lt;BR /&gt;
Also, The issue is not happening with SINGAPORE (ABC) which also has a space in between&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 14:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422553#M121335</guid>
      <dc:creator>amahesh3</dc:creator>
      <dc:date>2019-08-02T14:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422554#M121336</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
Can you please advise on how I can check the field extraction configuration ?&lt;/P&gt;

&lt;P&gt;I tried searching around and came across this &lt;BR /&gt;
(?i)^(?:[^ ]* ){2}(?:[+-]\d+ )?(?P[^ ]*)\s+(?P[^ ]+) - (?P.+)&lt;/P&gt;

&lt;P&gt;Please let me know if this is correct and also explain to me how it is accommodating the space in "SINGAPORE (ABC)" and not the space in other location names &lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 14:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422554#M121336</guid>
      <dc:creator>amahesh3</dc:creator>
      <dc:date>2019-08-02T14:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422555#M121337</link>
      <description>&lt;P&gt;You still have not provided an example of a full event.  When you do I can provide you a solution for your issue.  If it contains sensitive information, just change the values, but keep the formatting.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 16:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422555#M121337</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-08-02T16:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422556#M121338</link>
      <description>&lt;P&gt;First things first... The regular expression you pasted won't look right to anyone looking at it here because it got eaten by the site's comment formatting engine. To paste anything with unusual characters like stars or greater than or less than symbols in their original, unaltered form, you'll need to surround them with code tags like this:&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
(?i)^(?:[^ ] ){2}(?:[+-]\d+ )?(?P[^ ])\s+(?P[^ ]+) - (?P.+)&lt;BR /&gt;
&lt;/CODE&gt;&lt;BR /&gt;
&lt;/PRE&gt;&lt;BR /&gt;
And then every character will appear exactly as it actually is at your end for other viewers, like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;(?i)^(?:[^ ] *){2}(?:[+-]\d+ )?(?P[^ ])\s+(?P[^ ]+) - (?P.+)&lt;/CODE&gt;&lt;BR /&gt;
(Neither of my examples here probably match your real regex, because your version didn't survive the site's formatting engine and I can't reliably guess what the correct regex actually looks like.)&lt;/P&gt;

&lt;P&gt;Now, on to your issue.&lt;/P&gt;

&lt;P&gt;Purely speculation, but I see in your regular expression above that it contains a {2} which means to look for the previous token "exactly two times". Look at the below:&lt;/P&gt;

&lt;PRE&gt;
New York (ABC)
1   2    3
Washington DC (ABC)
1          2  3
Singapore (ABC)
1         2
Hong Kong (ABC)
1    2    3
HO CHI MINH CITY VIETNAM (ABC)
1  2   3    4    5       6
&lt;/PRE&gt;

&lt;P&gt;What I'm guessing is your actual regex which matches "Singapore (ABC) " would &lt;EM&gt;not&lt;/EM&gt; match "New York (ABC) ", or any of your other examples, because those others are a string containing non-space characters followed by a space character &lt;STRONG&gt;three or more times&lt;/STRONG&gt;, instead of &lt;STRONG&gt;exactly two times&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;That could be the problem if you let Splunk create the regex for the field extractions and the sample events you selected didn't happen include any locations with more spaces in the location names, Splunk may have done this without you realizing it because it generally tries to be as specific as possible based on your sample events when it creates the extraction regexes for you.&lt;/P&gt;

&lt;P&gt;This may or may not solve the issue for you (I can't know without seeing the actual raw events in their actual format and without knowing your actual unaltered regex, but you could try changing the {2} in the regex you found to {2,} instead (adding the comma without another number after means "match the previous token 2 &lt;STRONG&gt;or more&lt;/STRONG&gt; times" instead of just exactly two times as it currently does without the comma. In regular expressions {n,n} specifies a range of how many times the previous token should match. So for example if you wanted to match at least 3 but not more than 7 times, you would have &lt;STRONG&gt;{3,7}&lt;/STRONG&gt;. Having the comma with only the first or second number means basically:&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
{5} - this is the same as "exactly", or "exactly 5 times", or =5&lt;BR /&gt;
{5,} - this is the same as "equal to or greater than", or "5 or more times", or &amp;gt;=5&lt;BR /&gt;
{,5} - this is the same as "less than or equal to", or "5 or fewer times", or &amp;lt;=5&lt;BR /&gt;
{3,5} - this is the same as "from..to", or "3 to 5 times", or "&amp;gt;=3 and &amp;lt;=5"&lt;BR /&gt;
&lt;/PRE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:29:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422556#M121338</guid>
      <dc:creator>keith_d</dc:creator>
      <dc:date>2019-08-02T18:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422557#M121339</link>
      <description>&lt;P&gt;If what you are saying is true, then I should be getting location like&lt;BR /&gt;
WASHINGTON DC&lt;BR /&gt;
HO CHI&lt;BR /&gt;
HONG KONG&lt;BR /&gt;
NEW YORK&lt;/P&gt;

&lt;P&gt;I should be getting 2 words of each location right ?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 13:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422557#M121339</guid>
      <dc:creator>amahesh3</dc:creator>
      <dc:date>2019-08-05T13:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422558#M121340</link>
      <description>&lt;P&gt;That's correct, but one of those "words" is your "(ABC)", so you will only get at most one name for each location based on what I can see and make out of your regex.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Edit:&lt;/STRONG&gt; Actually, I just realized that what you're saying is correct, so in that case, I'm not sure what's going on. We'll need some sample raw events to compare with (if there's anything private/sensitive in them, just alter those items but keep the same formatting, i.e., upper case letters stay upper case, lower case letters stay lower case, numbers stay numbers, punctuation stays punctuation - and preferably the same punctuation so the regexes remain clear and answers can be more accurate.)&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 15:14:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422558#M121340</guid>
      <dc:creator>keith_d</dc:creator>
      <dc:date>2019-08-05T15:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Value in location field gets truncated when search is ran</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422559#M121341</link>
      <description>&lt;P&gt;A full example of your event could be handy. Depending on your full event data you can be a bit more precise with regex. You can use what ever precedes the location name and since you have parenthesis you can also use them as a boundary for your capture group&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt;&lt;BR /&gt;
event text whatever pre location SINGAPORE (ABC) event text &lt;BR /&gt;
event text other info pre location HO CHI MINH CITY VIETNAM (ABC) event text &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Regex:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;CODE&gt;location\s+(?&amp;lt;location&amp;gt;[\w\s]+\([\w\s]+\))&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Explanation:&lt;/STRONG&gt;&lt;BR /&gt;
Both names would be properly extracted since I bounded my capture group between "location" and a set of "( )" with whatever word and spaces inside. Whatever word composed by a-zA-Z0-9_ ( \w ) ou a blank character ( \s ) will be captured.&lt;BR /&gt;
&lt;STRONG&gt;Live test here:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://regex101.com/r/5lMFCJ/1"&gt;https://regex101.com/r/5lMFCJ/1&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 23:10:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Value-in-location-field-gets-truncated-when-search-is-ran/m-p/422559#M121341</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2019-08-05T23:10:30Z</dc:date>
    </item>
  </channel>
</rss>

