<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use the query that Field extractor generate to use in your search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-query-that-Field-extractor-generate-to-use-in/m-p/544119#M154132</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;If the fields are only visible to you but other can't .It means the extractions which you have created are in private.Make it global then others can make use of it.&lt;/P&gt;&lt;P&gt;If you want to put it in search then use the&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rex command&lt;/P&gt;&lt;P&gt;|rex "^[^&amp;gt;\n]*&amp;gt;\s+\w+&amp;lt;(?P&amp;lt;Portname&amp;gt;[^&amp;gt;]+)[^:\n]*:\s+(?P&amp;lt;Status&amp;gt;\w+) at &amp;lt;(?P&amp;lt;IP&amp;gt;[^:]+):(?P&amp;lt;Port&amp;gt;[^&amp;gt;]+)"&lt;/P&gt;&lt;P&gt;If this answer helps you then upvote it.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Mar 2021 06:05:10 GMT</pubDate>
    <dc:creator>Vardhan</dc:creator>
    <dc:date>2021-03-17T06:05:10Z</dc:date>
    <item>
      <title>How to use the query that Field extractor generate to use in your search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-query-that-Field-extractor-generate-to-use-in/m-p/544116#M154129</link>
      <description>&lt;P&gt;Hi, so I try to use Field Extractor (in Extract new fields) to extract some fields from raw logs to make a table. I have successfully show it on my end but other can't. So I want to apply the query that it auto generate in my own search. The query is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;^[^&amp;gt;\n]*&amp;gt;\s+\w+&amp;lt;(?P&amp;lt;Portname&amp;gt;[^&amp;gt;]+)[^:\n]*:\s+(?P&amp;lt;Status&amp;gt;\w+) at &amp;lt;(?P&amp;lt;IP&amp;gt;[^:]+):(?P&amp;lt;Port&amp;gt;[^&amp;gt;]+)&lt;/LI-CODE&gt;&lt;P&gt;How do I apply it to Splunk search?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 05:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-query-that-Field-extractor-generate-to-use-in/m-p/544116#M154129</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2021-03-17T05:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to use the query that Field extractor generate to use in your search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-query-that-Field-extractor-generate-to-use-in/m-p/544119#M154132</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;If the fields are only visible to you but other can't .It means the extractions which you have created are in private.Make it global then others can make use of it.&lt;/P&gt;&lt;P&gt;If you want to put it in search then use the&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rex command&lt;/P&gt;&lt;P&gt;|rex "^[^&amp;gt;\n]*&amp;gt;\s+\w+&amp;lt;(?P&amp;lt;Portname&amp;gt;[^&amp;gt;]+)[^:\n]*:\s+(?P&amp;lt;Status&amp;gt;\w+) at &amp;lt;(?P&amp;lt;IP&amp;gt;[^:]+):(?P&amp;lt;Port&amp;gt;[^&amp;gt;]+)"&lt;/P&gt;&lt;P&gt;If this answer helps you then upvote it.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 06:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-query-that-Field-extractor-generate-to-use-in/m-p/544119#M154132</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-17T06:05:10Z</dc:date>
    </item>
  </channel>
</rss>

