<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uses Transform Field Extraction-Delimiter in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564221#M196538</link>
    <description>&lt;P&gt;It's good when I write a props and transforms configuration files. But, I am trying to extract fields at/from the SPLUNK web console layer....like from the menu options under "Setting" and "Fields"&amp;nbsp; ...how would I&amp;nbsp; write REGEX...your provided code (REGEX) is not grouping data as expected .&amp;nbsp; &amp;nbsp;Thank. you so much, appreciated.&lt;/P&gt;</description>
    <pubDate>Sun, 22 Aug 2021 16:20:54 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2021-08-22T16:20:54Z</dc:date>
    <item>
      <title>Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564203#M196526</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I was using Transform type Field Extraction, I have an issue to select my Delimiter and facing some errors (not extracting fields as expected). Please see below the Raw Event and the parameters used for it. Thank you so much .....greatly appreciated your support.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Raw Event&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"time_stamp":"2021-08-21 19:14:32 EST","user_type":"TESTUSER","file_source_cd":"1","ip_addr":"103.91.224.65","session_id":"ABSkbE7IWb3ZU52VZk=","tsn":"490937st,"request_id":"3ee0a-0c1712196e7-317f2700-d751c8e","user_id":"EASA68A7-780DEA22","return_cd":"10","app_name":"ALAO","event_type":"TEST_AUTH","event_id":"VIEW_LIST_RESPONSE","vardata":"[]","&lt;/SPAN&gt;&lt;SPAN&gt;uri&lt;/SPAN&gt;&lt;SPAN&gt;":&lt;/SPAN&gt;&lt;A href="https://wap-prod-taxpro.tcc.irs.gov:10400/api/web-apps/taxpro/authorizations/taxpayer" target="_blank" rel="noopener"&gt;https://wap-prod- /api/web-apps /authorizations&lt;/A&gt;&lt;SPAN&gt;,"error_msg":""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Parameters used:&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malekmo_2-1629606569934.png" style="width: 734px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15656iE832C81778EEF385/image-dimensions/734x279?v=v2" width="734" height="279" role="button" title="malekmo_2-1629606569934.png" alt="malekmo_2-1629606569934.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 04:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564203#M196526</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-22T04:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564215#M196534</link>
      <description>&lt;P&gt;How about this?&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;[&amp;lt;your sourcetype&amp;gt;]&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;REPORT-xmlext = field-extractor&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;[field-extractor]&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;REGEX = \"*([^\"]+)\":\"([^\"|:]*)\",*|\"(time_stamp)\":\"([^\"]+)|\"(uri)\":([^,]+)&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;FORMAT = $1::$2&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;MV_ADD = true&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;REPEAT_MATCH = true&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN&gt;If you like it, please mark it as the solution. &amp;nbsp;Thank you!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 15:18:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564215#M196534</guid>
      <dc:creator>jwalthour</dc:creator>
      <dc:date>2021-08-22T15:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564221#M196538</link>
      <description>&lt;P&gt;It's good when I write a props and transforms configuration files. But, I am trying to extract fields at/from the SPLUNK web console layer....like from the menu options under "Setting" and "Fields"&amp;nbsp; ...how would I&amp;nbsp; write REGEX...your provided code (REGEX) is not grouping data as expected .&amp;nbsp; &amp;nbsp;Thank. you so much, appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 16:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564221#M196538</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-22T16:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564224#M196539</link>
      <description>&lt;P&gt;Go to Settings &amp;gt; Fields &amp;gt; Field transformations &amp;gt; New Field Transformation and add this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="A0F12FEE-7670-459D-A08E-2C6690D46D89.jpeg" style="width: 1170px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15657i745938FFCF73A404/image-size/medium?v=v2&amp;amp;px=400" role="button" title="A0F12FEE-7670-459D-A08E-2C6690D46D89.jpeg" alt="A0F12FEE-7670-459D-A08E-2C6690D46D89.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Save this. Then, go to Settings &amp;gt; Fields &amp;gt; Field extractions &amp;gt; New Field Extractions and as this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="54A3FA5A-43B6-495E-A8FF-880E6F06A093.jpeg" style="width: 1170px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15658i639F4B32CF219732/image-size/medium?v=v2&amp;amp;px=400" role="button" title="54A3FA5A-43B6-495E-A8FF-880E6F06A093.jpeg" alt="54A3FA5A-43B6-495E-A8FF-880E6F06A093.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Try that and let me know how it’s working for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 16:41:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564224#M196539</guid>
      <dc:creator>jwalthour</dc:creator>
      <dc:date>2021-08-22T16:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564225#M196540</link>
      <description>&lt;P&gt;Yes, your codes/instructions are right for regex-based option. But, I want to use delimiter based.....with giving the field names different than what is in the events. Thank you so much again, appreciated!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 17:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564225#M196540</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-22T17:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564234#M196542</link>
      <description>&lt;P class="p1"&gt;&lt;SPAN&gt;I’m not giving up yet. Is your field layout always the same? I wrote a dynamic field extraction before. However, now I’m thinking it’s static from what you’re saying. If so, try this in Settings &amp;gt; Fields &amp;gt; Field Extractions &amp;gt; Add New Field Extraction in the regex text box:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s2"&gt;\"time_stamp\":\"(?P&amp;lt;field1&amp;gt;[^\"]+)\",\"user_type\":\"(?P&amp;lt;field2&amp;gt;[^\"]+)\",\"file_source_cd\":\"(?P&amp;lt;field3&amp;gt;[^\"]+)\",\"ip_addr\":\"(?P&amp;lt;field4&amp;gt;[^\"]+)\",\"session_id\":\"(?P&amp;lt;field5&amp;gt;[^\"]+)\",\"tsn\":\"(?P&amp;lt;field6&amp;gt;[^,]+)\"*,\"request_id\":\"(?P&amp;lt;field7&amp;gt;[^\"]+)\",\"user_id\":\"(?P&amp;lt;field8&amp;gt;[^\"]+)\",\"return_cd\":\"(?P&amp;lt;field9&amp;gt;[^\"]+)\",\"app_name\":\"(?P&amp;lt;field10&amp;gt;[^\"]+)\",\"event_type\":\"(?P&amp;lt;field11&amp;gt;[^\"]+)\",\"event_id\":\"(?P&amp;lt;field12&amp;gt;[^\"]+)\",\"vardata\":\"(?P&amp;lt;field13&amp;gt;[^\"]+)\",\"uri\":(?P&amp;lt;field14&amp;gt;[^\"]+),\"error_msg\":\"(?P&amp;lt;field15&amp;gt;[^\"]*)\"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s2"&gt;I just labeled the fields 1-15. You can call them whatever your want. If this is still not quite to order. You could create each as a separate field extraction (eg, ,\"error_msg\":\"(?P&amp;lt;field15&amp;gt;[^\"]*)\") so they can be in different orders.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN&gt;Let me know how this works or doesn’t.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 17:59:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564234#M196542</guid>
      <dc:creator>jwalthour</dc:creator>
      <dc:date>2021-08-22T17:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564237#M196543</link>
      <description>&lt;P&gt;Thank you so much, appreciated!!!&lt;/P&gt;&lt;P&gt;Yes field layout always the same and your codes are working as it is written for.&lt;/P&gt;&lt;P&gt;But, my issue using &lt;STRONG&gt;delimiter-based&amp;nbsp;&lt;/STRONG&gt;field extraction&lt;/P&gt;&lt;P&gt;Like&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Setting-&amp;gt;Fields-&amp;gt;Field transformations (&lt;STRONG&gt;see screenshot below&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;Under &lt;STRONG&gt;Field transformations&lt;/STRONG&gt;&amp;nbsp;, Select the &lt;STRONG&gt;Type Delimiter-based.&amp;nbsp;&lt;/STRONG&gt;My issue, with choosing the Delimiter value. I used &lt;STRONG&gt;","&lt;/STRONG&gt; in delimiter field, but not extracted/group fields values. Some of the field values are overlap with each other.&amp;nbsp; Thank you again, appreciated&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malekmo_0-1629659605346.png" style="width: 755px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15663i32E912AB0ECD3BDF/image-dimensions/755x287?v=v2" width="755" height="287" role="button" title="malekmo_0-1629659605346.png" alt="malekmo_0-1629659605346.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 19:18:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564237#M196543</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-22T19:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564238#M196544</link>
      <description>&lt;P&gt;I’m suggesting you not use delimited-based field extraction. You have much more flexibility and control with regex-based. Then, you don’t the errors you mention.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 19:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564238#M196544</guid>
      <dc:creator>jwalthour</dc:creator>
      <dc:date>2021-08-22T19:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Uses Transform Field Extraction-Delimiter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564239#M196545</link>
      <description>&lt;P&gt;That makes sense. Thank you so much appreciated!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 19:29:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uses-Transform-Field-Extraction-Delimiter/m-p/564239#M196545</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-22T19:29:19Z</dc:date>
    </item>
  </channel>
</rss>

