<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to create fields from _raw field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89465#M22937</link>
    <description>&lt;P&gt;How to I set this in props.conf so it'll create a field at index time?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jul 2012 16:21:31 GMT</pubDate>
    <dc:creator>jangid</dc:creator>
    <dc:date>2012-07-05T16:21:31Z</dc:date>
    <item>
      <title>how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89459#M22931</link>
      <description>&lt;P&gt;How to create a field from _raw field?&lt;/P&gt;

&lt;P&gt;my _raw field have some common pattern&lt;BR /&gt;
e.g.&lt;/P&gt;

&lt;P&gt;I0703 15:07:20.627351  3108 logger_c.cpp:42] PROCINFO.b:72 [mjangid] [User] [PROCINFO] PORT_NUMBER=6 NUM_PROGRAMS=1 START_TIME=1341322102 PID=4064 ACCOUNT=mjangid USER=mjangid TERMINAL_JBASE=ntcon TERMINAL_OS=ntcon DATABASE=default TTY=CONIN$ LANGUAGE=C LISTENING_TIME=1341324438 MEM_FREE=0 MEM_USED=8769536 THREAD_TYPE_INT=1 THREAD_TYPE_TXT=Normal LICENSE=5122|100000 STATS_OPEN=8 STATS_READ=55 STATS_WRITE=17 STATS_DELETE=1 STATS_CLEARFILE=0 STATS_PERFORM=3 STATS_INPUT=63 UNUSED_1="" OPEN_FILES_VIRTUAL=4 OPEN_FILES_REAL=4 USER_ROOT="" PROCESS_TXT="" STATS_READFRM=0 STATS_WRITEFRM=0 STATS_TOTALFRM=0 STATS_LOCKRETRY=0 PROGRAM=jsh LINE_NUMBER=103 SOURCE_NAME=CommandNext.b UNUSED_2="" UNUSED_3="" STATUS_TXT="Program at keyboard INPUT" STATUS_INT=14 CPU_USR=54.09 CPU_SYS=0.00 CPU_USR_CHILD=0.00 CPU_SYS_CHILD=0.00 USER_THREAD="" &lt;/P&gt;

&lt;P&gt;from initial part of the log&lt;BR /&gt;
I0703 15:07:20.627351  3108 logger_c.cpp:42] PROCINFO.b:72 [mjangid] [User] [PROCINFO] &lt;/P&gt;

&lt;P&gt;Now I want to create some fields for whole app&lt;/P&gt;

&lt;P&gt;processid = 3108&lt;BR /&gt;
user_name = mjangid&lt;BR /&gt;
user_name_2 = User&lt;BR /&gt;
section = PROCINFO&lt;/P&gt;

&lt;P&gt;any idea how to extract above field?&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:01:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89459#M22931</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2020-09-28T12:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89460#M22932</link>
      <description>&lt;P&gt;So the format of your data means that Splunk can automatically extract the data as they are key=value pairs. E.g. you already have user extracted as USER.&lt;/P&gt;

&lt;P&gt;Instead, what you want to do is create field aliases for those fields so Splunk creates a different field name for those fields which you can match, since Splunk is already doing the extraction there is little point in defining your own new extractions.&lt;/P&gt;

&lt;P&gt;Have a look here for how to setup aliasing.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addaliasestofields" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addaliasestofields&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Quick regex that will pull the bits out of the first line;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\w+\s\d+:\d+:\d+.\d+\s+(?&amp;lt;processid&amp;gt;\d+)\s\w+.\w+:\d+\]\s\w+.\w:\d+\s\[(?&amp;lt;user_name&amp;gt;[\w]+)\]\s\[(?&amp;lt;user_name_2&amp;gt;\w+)\]\s\[(?&amp;lt;section&amp;gt;\w+)\]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bear in mind that I've created that based just on that one example and really you should follow my advice above in this answer and in the comment below.&lt;/P&gt;

&lt;P&gt;Finally, when using Splunk you don't want to extract values into field names like user_name or user_name_2. You may not hit problems now and it may do what you want, but you should really look at the Common Information Model and change your field names to match;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/UnderstandandusetheCommonInformationModel" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/UnderstandandusetheCommonInformationModel&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89460#M22932</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2020-09-28T12:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89461#M22933</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;BR /&gt;
I know the key/pair extraction and don't want to create alias.&lt;/P&gt;

&lt;P&gt;I want to create a new field from my _raw field&lt;/P&gt;

&lt;P&gt;e.g.&lt;/P&gt;

&lt;P&gt;I0703 15:07:20.627351  3108 logger_c.cpp:42] PROCINFO.b:72 [mjangid] [User] [PROCINFO] ...&lt;/P&gt;

&lt;P&gt;processid = 3108 --&amp;gt; this is my processID will change very frequently&lt;/P&gt;

&lt;P&gt;user_name = mjangid --&amp;gt; system user&lt;BR /&gt;
user_name_2 = User --&amp;gt; application user&lt;BR /&gt;
section = PROCINFO --&amp;gt; my section&lt;/P&gt;

&lt;P&gt;all above information available in log but want to extract in field &lt;/P&gt;

&lt;P&gt;processid  SysUser  AppUser  Section&lt;/P&gt;

&lt;P&gt;3108       mjangid   User-1  PROCINFO&lt;BR /&gt;
910        mjangid   User-1  PROCINFO&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:01:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89461#M22933</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2020-09-28T12:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89462#M22934</link>
      <description>&lt;P&gt;If the detail is available within the log already and Splunk is pulling it at search time, why do you then want to write your own extractions to pull the same information again? Thats not really how Splunk works, or rather how you should use it. The search time extraction is highly optimized and the K/V pair extraction is really efficient, creating aliases for those to your expected fields would be far more efficient than running an extraction twice for the same data set. If you're sure you want to then have a look at my updated answer&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 08:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89462#M22934</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-07-05T08:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89463#M22935</link>
      <description>&lt;P&gt;Why don't you want to create aliases? It's hands down the smoothest and easiest solution to what you're trying to achieve.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 08:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89463#M22935</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-07-05T08:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89464#M22936</link>
      <description>&lt;P&gt;Thanks &lt;BR /&gt;
your updated answer resolve my issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thank you&lt;BR /&gt;
Manoj&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 10:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89464#M22936</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-07-05T10:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to create fields from _raw field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89465#M22937</link>
      <description>&lt;P&gt;How to I set this in props.conf so it'll create a field at index time?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-create-fields-from-raw-field/m-p/89465#M22937</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-07-05T16:21:31Z</dc:date>
    </item>
  </channel>
</rss>

