<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does extracted field search work for certain dates but not some other dates? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642232#M222471</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163001"&gt;@gnshah12345&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You may use the following regex expression for fetching the required "remote_user" field.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;\d{0,3}\.\d{0,3}\.\d{0,3}\.\d{0,3}\s\-\s(?&amp;lt;remote_user&amp;gt;.+)\[&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Kindly upvote, if found helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 06:41:53 GMT</pubDate>
    <dc:creator>seemanshu</dc:creator>
    <dc:date>2023-05-04T06:41:53Z</dc:date>
    <item>
      <title>Why does extracted field search work for certain dates but not some other dates?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642164#M222450</link>
      <description>&lt;P&gt;I created an extracted field called remote_user.&amp;nbsp; My search for certain dates do bring the field value properly. However the same search for some other dates do not bring the proper values. I checked the events and the extracted field is malformed on the dates having issues. The remote_user field value will be like "CompanyName John_doe".&amp;nbsp; The days when search is working the remote_user shows&amp;nbsp;"CompanyName John_doe".&amp;nbsp; The dates when the search is not working the field shows&amp;nbsp; value as "CompanyName". How can same extracted field works differently on different dates? Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642164#M222450</guid>
      <dc:creator>gnshah12345</dc:creator>
      <dc:date>2023-05-03T18:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why does extracted field search work for certain dates but not some other dates?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642169#M222452</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163001"&gt;@gnshah12345&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;If the field extraction is based on user provided regex, kindly share the same in the response with a sample data, will be helpful in finding the right cause.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:37:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642169#M222452</guid>
      <dc:creator>seemanshu</dc:creator>
      <dc:date>2023-05-03T18:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why does extracted field search work for certain dates but not some other dates?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642178#M222456</link>
      <description>&lt;P&gt;The below is sample. The extracted field is highlighted.&lt;/P&gt;&lt;P&gt;May 3 11:26:01 linux_1 request-instance SoftCert 10.10.20.30 - &lt;STRONG&gt;&lt;EM&gt;Brew Bar John Doe_123456_UE&lt;/EM&gt;&lt;/STRONG&gt; [03/May/2023:11:25:55.509 -0400] "GET /rest/BROk305031.xml?ink=202305031525554263206 HTTP/1.1" 404 196 36580 1 25135 brew.bar.com /rest 749 "OU=123456+CN= Brew Bar John Doe,OU=ny,O=Brew Bar Joint,C=us" cc045c0a-e9a9-11ed-a6e5-0050568916c1 "x509: TLSV12: 30" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0"&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 19:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642178#M222456</guid>
      <dc:creator>gnshah12345</dc:creator>
      <dc:date>2023-05-03T19:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why does extracted field search work for certain dates but not some other dates?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642179#M222457</link>
      <description>&lt;P&gt;I used regular expression for field extraction.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 19:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642179#M222457</guid>
      <dc:creator>gnshah12345</dc:creator>
      <dc:date>2023-05-03T19:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why does extracted field search work for certain dates but not some other dates?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642232#M222471</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163001"&gt;@gnshah12345&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You may use the following regex expression for fetching the required "remote_user" field.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;\d{0,3}\.\d{0,3}\.\d{0,3}\.\d{0,3}\s\-\s(?&amp;lt;remote_user&amp;gt;.+)\[&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Kindly upvote, if found helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 06:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642232#M222471</guid>
      <dc:creator>seemanshu</dc:creator>
      <dc:date>2023-05-04T06:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why does extracted field search work for certain dates but not some other dates?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642241#M222474</link>
      <description>&lt;P&gt;The question doesn't seem to be related to dates - unless you can show two different raw events, one for which your regex works as desired, one for which not. &amp;nbsp;Additionally, unless you can demonstrate your regex, there is no way to diagnose.&lt;/P&gt;&lt;P&gt;But ultimately, what is the significance of this string preceding the bracketed date, namely "Brew Bar John Doe_123456_UE"? &amp;nbsp;According to your description, the value you want is "&lt;STRONG&gt;&lt;EM&gt;Brew Bar John Doe&lt;/EM&gt;&lt;/STRONG&gt;". &amp;nbsp;If your description is accurate, this is the value of CN attribute in that embedded LDAP node, except that embedded message contains a nonstandard delimiter ("+" instead of space), and some inconvenient spacing, both can be fixed easily.&lt;/P&gt;&lt;P&gt;Instead of trying to reinvent regex, I suggest that you use Splunk supported extractions when applicable. &amp;nbsp;They are more robust. &amp;nbsp;In your case, the log contains a segment that is NCSA/Apache access log. &amp;nbsp;Splunk comes with access-request and access-extractions for such. &amp;nbsp;For example,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed "s/\+/,/g s/= */=/g" ``` handle little quirks in data ```
| extract access-request ``` but this is robust ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will give you&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;C&lt;/TD&gt;&lt;TD width="51.765625px" height="25px"&gt;CN&lt;/TD&gt;&lt;TD width="51.765625px" height="25px"&gt;O&lt;/TD&gt;&lt;TD width="68.609375px" height="25px"&gt;OU&lt;/TD&gt;&lt;TD width="137.828125px" height="25px"&gt;file&lt;/TD&gt;&lt;TD width="212.609375px" height="25px"&gt;ink&lt;/TD&gt;&lt;TD width="67.4375px" height="25px"&gt;method&lt;/TD&gt;&lt;TD width="41.390625px" height="25px"&gt;root&lt;/TD&gt;&lt;TD width="243.46875px" height="25px"&gt;uri&lt;/TD&gt;&lt;TD width="92.734375px" height="25px"&gt;uri_domain&lt;/TD&gt;&lt;TD width="180.484375px" height="25px"&gt;uri_path&lt;/TD&gt;&lt;TD width="243.46875px" height="25px"&gt;uri_query&lt;/TD&gt;&lt;TD width="79.171875px" height="25px"&gt;version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="91px"&gt;us&lt;/TD&gt;&lt;TD width="51.765625px" height="91px"&gt;Brew Bar John Doe&lt;/TD&gt;&lt;TD width="51.765625px" height="91px"&gt;Brew Bar Joint&lt;/TD&gt;&lt;TD width="68.609375px" height="91px"&gt;123456&lt;/TD&gt;&lt;TD width="137.828125px" height="91px"&gt;BROk305031.xml&lt;/TD&gt;&lt;TD width="212.609375px" height="91px"&gt;202305031525554263206&lt;/TD&gt;&lt;TD width="67.4375px" height="91px"&gt;GET&lt;/TD&gt;&lt;TD width="41.390625px" height="91px"&gt;rest&lt;/TD&gt;&lt;TD width="243.46875px" height="91px"&gt;/rest/BROk305031.xml?ink=202305031525554263206&lt;/TD&gt;&lt;TD width="92.734375px" height="91px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="180.484375px" height="91px"&gt;/rest/BROk305031.xml&lt;/TD&gt;&lt;TD width="243.46875px" height="91px"&gt;ink=202305031525554263206&lt;/TD&gt;&lt;TD width="79.171875px" height="91px"&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;Alternatively, you can use&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed "s/\+/,/g s/= */=/g"
| extract access-extractions&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;C&lt;/TD&gt;&lt;TD&gt;CN&lt;/TD&gt;&lt;TD&gt;O&lt;/TD&gt;&lt;TD&gt;OU&lt;/TD&gt;&lt;TD&gt;ink&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;us&lt;/TD&gt;&lt;TD&gt;Brew Bar John Doe&lt;/TD&gt;&lt;TD&gt;Brew Bar Joint&lt;/TD&gt;&lt;TD&gt;123456&lt;/TD&gt;&lt;TD&gt;202305031525554263206&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 04 May 2023 08:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-extracted-field-search-work-for-certain-dates-but-not/m-p/642241#M222474</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-05-04T08:09:06Z</dc:date>
    </item>
  </channel>
</rss>

