<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How does automatic key=value extraction works? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58553#M14347</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;we have a logfile that contains key=value pairs. &lt;BR /&gt;
Usually Splunks automatic field extraction is working fine and is showing the fields. But...when i want to do a search like e.g. this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/opt/tomcat/logs/san.log" tag="*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk tells me, that the field "tag" doesn´t exist.&lt;/P&gt;

&lt;P&gt;But when i use:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/opt/tomcat/logs/san.log" | search tag="whateverilookfor*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;i get the results as wished but also a message on top of the window saying: &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Encountered an unexpected error while&lt;BR /&gt;
parsing intentions.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;What is happening here and how can i avoid this?&lt;/P&gt;</description>
    <pubDate>Wed, 23 May 2012 17:42:17 GMT</pubDate>
    <dc:creator>tpaulsen</dc:creator>
    <dc:date>2012-05-23T17:42:17Z</dc:date>
    <item>
      <title>How does automatic key=value extraction works?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58553#M14347</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;we have a logfile that contains key=value pairs. &lt;BR /&gt;
Usually Splunks automatic field extraction is working fine and is showing the fields. But...when i want to do a search like e.g. this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/opt/tomcat/logs/san.log" tag="*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk tells me, that the field "tag" doesn´t exist.&lt;/P&gt;

&lt;P&gt;But when i use:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/opt/tomcat/logs/san.log" | search tag="whateverilookfor*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;i get the results as wished but also a message on top of the window saying: &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Encountered an unexpected error while&lt;BR /&gt;
parsing intentions.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;What is happening here and how can i avoid this?&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2012 17:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58553#M14347</guid>
      <dc:creator>tpaulsen</dc:creator>
      <dc:date>2012-05-23T17:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: How does automatic key=value extraction works?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58554#M14348</link>
      <description>&lt;P&gt;&lt;CODE&gt;tag&lt;/CODE&gt; is probably a reserved word, since it refers to tagging of information. See the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Abouttagsandaliases"&gt;Knowledge Manager&lt;/A&gt; section in the docs.&lt;/P&gt;

&lt;P&gt;Maybe that only applies when it comes before the first pipe. However, I believe that &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/opt/tomcat/logs/san.log" "tag=*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;would give you what you want, i.e. enclosing the statement in double quotes.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2012 19:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58554#M14348</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-23T19:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: How does automatic key=value extraction works?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58555#M14349</link>
      <description>&lt;P&gt;Thank you Kristian, that was exactly the problem. Tag is a reserved word, so it shouldn´t be used in the Logevent as a fieldname. We change the fieldname to ltag, now it is working. Best, Thomas&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2013 11:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-automatic-key-value-extraction-works/m-p/58555#M14349</guid>
      <dc:creator>tpaulsen</dc:creator>
      <dc:date>2013-03-07T11:08:31Z</dc:date>
    </item>
  </channel>
</rss>

