<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: specifying field in Field Extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560714#M159368</link>
    <description>&lt;P&gt;Thanks for the quick reply&lt;/P&gt;&lt;P&gt;But queries return nothing if &lt;STRONG&gt;in event&lt;/STRONG&gt; part is added at the end of the line,&amp;nbsp; after removing it they start working again.&lt;/P&gt;&lt;P&gt;btw, I tried to put entire Regex in quotes then &lt;STRONG&gt;in event&lt;/STRONG&gt; part (as u can see in screenshot), and w/o quotes but nothing changed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rabbit_0-1627241285809.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15221i0688F0F7127FDD92/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Rabbit_0-1627241285809.png" alt="Rabbit_0-1627241285809.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Jul 2021 19:28:15 GMT</pubDate>
    <dc:creator>Rabbit</dc:creator>
    <dc:date>2021-07-25T19:28:15Z</dc:date>
    <item>
      <title>specifying field in Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560686#M159354</link>
      <description>&lt;P&gt;in search, w/ &lt;STRONG&gt;rex&lt;/STRONG&gt; command I can specify which field I want to apply the Regex as following example&lt;BR /&gt;| rex &lt;STRONG&gt;field&lt;/STRONG&gt;=event "My Custom regex...."&lt;/P&gt;&lt;P&gt;But if I want to register the same regex in Field Extraction option (to have it reusable object w/ my team) I don't see any option to specify the field. I assume it register it to entire&lt;STRONG&gt; _raw&lt;/STRONG&gt; as default.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any idea if I can specify the field when I create a Field with "Field Extraction" ?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 21:42:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560686#M159354</guid>
      <dc:creator>Rabbit</dc:creator>
      <dc:date>2021-07-24T21:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: specifying field in Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560691#M159358</link>
      <description>&lt;P&gt;Can you save it as a macro that your team can reuse?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 22:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560691#M159358</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-24T22:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: specifying field in Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560697#M159363</link>
      <description>&lt;P&gt;We're planning to have custom fields so people can directly search by those fields.&amp;nbsp; Field Extraction works well only concern of mine is not able to specify the fields which can cause performance difficulties.&lt;/P&gt;&lt;P&gt;I assume there is a difference between parsing from only the event versus from entire _raw.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, I don't want to force developers to use&amp;nbsp;&lt;SPAN&gt;back tick character for macro(s).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 03:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560697#M159363</guid>
      <dc:creator>Rabbit</dc:creator>
      <dc:date>2021-07-25T03:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: specifying field in Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560703#M159366</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236788"&gt;@Rabbit&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes, putting a regex in field extractor it search in all _raw,&lt;/P&gt;&lt;P&gt;but you can limit the search to an already extracted field (the same thing of field=event in rex command) adding "in event" (without quotes obviously) at the end of the expression, in other words,&amp;nbsp; please try to put this expression in field extractor:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;My Custom regex.... in event&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 08:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560703#M159366</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-25T08:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: specifying field in Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560714#M159368</link>
      <description>&lt;P&gt;Thanks for the quick reply&lt;/P&gt;&lt;P&gt;But queries return nothing if &lt;STRONG&gt;in event&lt;/STRONG&gt; part is added at the end of the line,&amp;nbsp; after removing it they start working again.&lt;/P&gt;&lt;P&gt;btw, I tried to put entire Regex in quotes then &lt;STRONG&gt;in event&lt;/STRONG&gt; part (as u can see in screenshot), and w/o quotes but nothing changed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rabbit_0-1627241285809.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15221i0688F0F7127FDD92/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Rabbit_0-1627241285809.png" alt="Rabbit_0-1627241285809.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 19:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560714#M159368</guid>
      <dc:creator>Rabbit</dc:creator>
      <dc:date>2021-07-25T19:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: specifying field in Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560735#M159377</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236788"&gt;@Rabbit&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you share your regex and a sample of your logs?&lt;/P&gt;&lt;P&gt;I used many times "in fieldname" in my field extraction.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 06:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/specifying-field-in-Field-Extraction/m-p/560735#M159377</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-26T06:13:48Z</dc:date>
    </item>
  </channel>
</rss>

