<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Team , I need Field extraction of status Error and INFO status in logs . in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531695#M150176</link>
    <description>&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;ERROR&lt;/STRONG&gt; [monki_HMCatalogSyncJob::de.hybris.platform.servicelayer.internal.jalo.ServicelayerJob] -[J= U= C=] (monki) (0000MM1K) [CatalogVersionSyncJob] Finished synchronization in 0d 00h:00m:07s:499ms. There were errors during the synchronization! &lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;​&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;INFO&lt;/STRONG&gt; [monki_HMCatalogSyncJob::de.hybris.platform.servicelayer.internal.jalo.ServicelayerJob] -[J= U= C=] (monki) (0000ML9S) [CatalogVersionSyncJob] Finished synchronization in 0d 00h:00m:17s:091ms. No errors. &lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 02 Dec 2020 13:51:57 GMT</pubDate>
    <dc:creator>Hemant1</dc:creator>
    <dc:date>2020-12-02T13:51:57Z</dc:date>
    <item>
      <title>Hi Team , I need Field extraction of status Error and INFO status in logs .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531695#M150176</link>
      <description>&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;ERROR&lt;/STRONG&gt; [monki_HMCatalogSyncJob::de.hybris.platform.servicelayer.internal.jalo.ServicelayerJob] -[J= U= C=] (monki) (0000MM1K) [CatalogVersionSyncJob] Finished synchronization in 0d 00h:00m:07s:499ms. There were errors during the synchronization! &lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;​&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;INFO&lt;/STRONG&gt; [monki_HMCatalogSyncJob::de.hybris.platform.servicelayer.internal.jalo.ServicelayerJob] -[J= U= C=] (monki) (0000ML9S) [CatalogVersionSyncJob] Finished synchronization in 0d 00h:00m:17s:091ms. No errors. &lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Dec 2020 13:51:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531695#M150176</guid>
      <dc:creator>Hemant1</dc:creator>
      <dc:date>2020-12-02T13:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team , I need Field extraction of status Error and INFO status in logs .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531699#M150178</link>
      <description>&lt;P&gt;Which parts of these events do you want?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 13:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531699#M150178</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-12-02T13:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team , I need Field extraction of status Error and INFO status in logs .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531781#M150207</link>
      <description>&lt;P&gt;hi, this is a simple extraction. Do events always start with the status? If yes, it will look something like:&lt;BR /&gt;&lt;SPAN&gt;| rex field=_raw "(?&amp;lt;status&amp;gt;^\w+)&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can use regex101.com to fine tune the regex if it is not working.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 22:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531781#M150207</guid>
      <dc:creator>daisy_st</dc:creator>
      <dc:date>2020-12-02T22:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team , I need Field extraction of status Error and INFO status in logs .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531814#M150223</link>
      <description>&lt;P&gt;i need to extract INFO and Error part&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 05:58:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531814#M150223</guid>
      <dc:creator>Hemant1</dc:creator>
      <dc:date>2020-12-03T05:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team , I need Field extraction of status Error and INFO status in logs .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531838#M150231</link>
      <description>&lt;P&gt;What is wrong with what&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229073"&gt;@daisy_st&lt;/a&gt;&amp;nbsp; suggested?&lt;/P&gt;&lt;P&gt;One reason it might not be working is that the information you provided is not your actual raw event. If that is the case, please provide some real examples.&lt;/P&gt;&lt;P&gt;Another possibility is that you are not looking for search time / SPL extraction but you want to know how to extract this at indexing time. Please can you clarify?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 09:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Hi-Team-I-need-Field-extraction-of-status-Error-and-INFO-status/m-p/531838#M150231</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-12-03T09:49:11Z</dc:date>
    </item>
  </channel>
</rss>

