<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Field Extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Field-Extraction/m-p/77782#M19662</link>
    <description>&lt;P&gt;Field names in Splunk must contain only alphabetic characters, numbers and underscore. The name may not begin with a number. In some cases, spaces are allowed, but not in automatic field extraction.&lt;/P&gt;

&lt;P&gt;I expect that this is what is causing your problem. There are potentially ways around this:&lt;/P&gt;

&lt;P&gt;General field extraction info: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Addfieldsatsearchtime"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Addfieldsatsearchtime&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;More detailed info - probably the most useful page: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Tons of details here (look halfway down the page for Field Extractions): &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jun 2012 18:50:13 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-06-18T18:50:13Z</dc:date>
    <item>
      <title>Splunk Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Field-Extraction/m-p/77781#M19661</link>
      <description>&lt;P&gt;Out of the box, Splunk performs field extractions of name/value pairs separated by an "=" sign. We would like to know what special characters disrupt this tagging. For instance, name[subname]=value&lt;BR /&gt;
name;subname=value&lt;BR /&gt;
name#subname=value&lt;/P&gt;

&lt;P&gt;will not tag appropriately. This does tag appropriately -&lt;/P&gt;

&lt;P&gt;name_subname=value&lt;/P&gt;

&lt;P&gt;How are other special characters handled?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Field-Extraction/m-p/77781#M19661</guid>
      <dc:creator>sgarvin55</dc:creator>
      <dc:date>2012-06-18T14:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Field-Extraction/m-p/77782#M19662</link>
      <description>&lt;P&gt;Field names in Splunk must contain only alphabetic characters, numbers and underscore. The name may not begin with a number. In some cases, spaces are allowed, but not in automatic field extraction.&lt;/P&gt;

&lt;P&gt;I expect that this is what is causing your problem. There are potentially ways around this:&lt;/P&gt;

&lt;P&gt;General field extraction info: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Addfieldsatsearchtime"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Addfieldsatsearchtime&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;More detailed info - probably the most useful page: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Tons of details here (look halfway down the page for Field Extractions): &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2012 18:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Field-Extraction/m-p/77782#M19662</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-06-18T18:50:13Z</dc:date>
    </item>
  </channel>
</rss>

