<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help to use EXTRACT in props.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/help-to-use-EXTRACT-in-props-conf/m-p/528953#M149343</link>
    <description>&lt;P&gt;yeah well I guess I have the solution again... *facepalm*.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've made an field extraction via splunk gui - settings - fields - field extraction and looked at the output. there it said the name of the extraction was&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EXTRACT-src_ip,bits,tcp_state&lt;/LI-CODE&gt;&lt;P&gt;so using this in my props.conf instead of only -fields made it work.... gosh.&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps anyone who comes across this little problem.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Nov 2020 11:08:07 GMT</pubDate>
    <dc:creator>avoelk</dc:creator>
    <dc:date>2020-11-11T11:08:07Z</dc:date>
    <item>
      <title>help to use EXTRACT in props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-to-use-EXTRACT-in-props-conf/m-p/528947#M149341</link>
      <description>&lt;P&gt;I've been trying to extract fields from a log at search time with only the help of props.conf. in the spunk docu I read that EXTRACT would be good in that case, especially cause I try to extract multiple fields at once.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is my EXTRACT in props.conf so far:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EXTRACT-fields = (?P&amp;lt;src_ip&amp;gt;\d*\.\d*\.\d*\.\d*)(?=\ \d* TCP_)\s(?P&amp;lt;bits&amp;gt;\d*)\s(?P&amp;lt;tcp_state&amp;gt;\w*_\w*)\s&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this would go on for a while with different fields but it doesn't work. what do I do wrong?&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is how the log looks like for example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2014-03-27 12:39:32 20 10.71.15.207 304 TCP_HIT 367 1470 GET http www.computerworld.com 80 /elqNow/elqFCS.js - - - - 23.196.74.53 application/x-javascript http://www.computerworld.com/s/article/9247206/Gameover_malware_takes_aim_at_Monster.com_and_CareerBuilder.com "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)" OBSERVED "Technology/Internet" - 163.252.254.201 23.44.202.53 52809&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for any help!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 10:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-to-use-EXTRACT-in-props-conf/m-p/528947#M149341</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2020-11-11T10:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: help to use EXTRACT in props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-to-use-EXTRACT-in-props-conf/m-p/528953#M149343</link>
      <description>&lt;P&gt;yeah well I guess I have the solution again... *facepalm*.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've made an field extraction via splunk gui - settings - fields - field extraction and looked at the output. there it said the name of the extraction was&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EXTRACT-src_ip,bits,tcp_state&lt;/LI-CODE&gt;&lt;P&gt;so using this in my props.conf instead of only -fields made it work.... gosh.&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps anyone who comes across this little problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 11:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-to-use-EXTRACT-in-props-conf/m-p/528953#M149343</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2020-11-11T11:08:07Z</dc:date>
    </item>
  </channel>
</rss>

