<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic field extraction for error message in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-for-error-message/m-p/669966#M229716</link>
    <description>&lt;P&gt;I want to extract the&amp;nbsp; following information make it as a field as "error message" .&lt;BR /&gt;&lt;BR /&gt;index=os source="/var/log/syslog" "*authentication failure*" OR "Generic preauthentication failure"&lt;BR /&gt;&lt;BR /&gt;Events example :&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Nov&lt;/SPAN&gt; &lt;SPAN class=""&gt;28&lt;/SPAN&gt; &lt;SPAN class=""&gt;01:02:31&lt;/SPAN&gt;&amp;nbsp;server1&amp;nbsp;&lt;SPAN class=""&gt;sssd&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;ldap_child&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;12010&lt;/SPAN&gt;&lt;SPAN&gt;]]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;initialize&lt;/SPAN&gt; &lt;SPAN class=""&gt;credentials&lt;/SPAN&gt; &lt;SPAN class=""&gt;using&lt;/SPAN&gt; &lt;SPAN class=""&gt;keytab&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;MEMORY:/etc/krb5.keytab&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Generic&lt;/SPAN&gt; &lt;SPAN class=""&gt;preauthentication&lt;/SPAN&gt; &lt;SPAN class=""&gt;failure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN class=""&gt;Unable&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;create&lt;/SPAN&gt; &lt;SPAN class=""&gt;GSSAPI-encrypted&lt;/SPAN&gt; &lt;SPAN class=""&gt;LDAP&lt;/SPAN&gt; &lt;SPAN class=""&gt;connection.&lt;BR /&gt;&lt;BR /&gt;Nov 28 01:02:29&amp;nbsp;server2&amp;nbsp;&amp;nbsp;proxy_child&lt;SPAN&gt;[&lt;/SPAN&gt;1939385&lt;SPAN&gt;]&lt;/SPAN&gt;: pam_unix&lt;SPAN&gt;(&lt;/SPAN&gt;system-auth-ac:auth&lt;SPAN&gt;)&lt;/SPAN&gt;: &lt;SPAN class=""&gt;authentication failure&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;logname= uid=0 euid=0 tty=ssh ruser= rhost=10.177.46.57 user=hippm&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Nov 2023 06:12:02 GMT</pubDate>
    <dc:creator>Hema_Nithya</dc:creator>
    <dc:date>2023-11-28T06:12:02Z</dc:date>
    <item>
      <title>field extraction for error message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-for-error-message/m-p/669966#M229716</link>
      <description>&lt;P&gt;I want to extract the&amp;nbsp; following information make it as a field as "error message" .&lt;BR /&gt;&lt;BR /&gt;index=os source="/var/log/syslog" "*authentication failure*" OR "Generic preauthentication failure"&lt;BR /&gt;&lt;BR /&gt;Events example :&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Nov&lt;/SPAN&gt; &lt;SPAN class=""&gt;28&lt;/SPAN&gt; &lt;SPAN class=""&gt;01:02:31&lt;/SPAN&gt;&amp;nbsp;server1&amp;nbsp;&lt;SPAN class=""&gt;sssd&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;ldap_child&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;12010&lt;/SPAN&gt;&lt;SPAN&gt;]]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;initialize&lt;/SPAN&gt; &lt;SPAN class=""&gt;credentials&lt;/SPAN&gt; &lt;SPAN class=""&gt;using&lt;/SPAN&gt; &lt;SPAN class=""&gt;keytab&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;MEMORY:/etc/krb5.keytab&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Generic&lt;/SPAN&gt; &lt;SPAN class=""&gt;preauthentication&lt;/SPAN&gt; &lt;SPAN class=""&gt;failure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN class=""&gt;Unable&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;create&lt;/SPAN&gt; &lt;SPAN class=""&gt;GSSAPI-encrypted&lt;/SPAN&gt; &lt;SPAN class=""&gt;LDAP&lt;/SPAN&gt; &lt;SPAN class=""&gt;connection.&lt;BR /&gt;&lt;BR /&gt;Nov 28 01:02:29&amp;nbsp;server2&amp;nbsp;&amp;nbsp;proxy_child&lt;SPAN&gt;[&lt;/SPAN&gt;1939385&lt;SPAN&gt;]&lt;/SPAN&gt;: pam_unix&lt;SPAN&gt;(&lt;/SPAN&gt;system-auth-ac:auth&lt;SPAN&gt;)&lt;/SPAN&gt;: &lt;SPAN class=""&gt;authentication failure&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;logname= uid=0 euid=0 tty=ssh ruser= rhost=10.177.46.57 user=hippm&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 06:12:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/field-extraction-for-error-message/m-p/669966#M229716</guid>
      <dc:creator>Hema_Nithya</dc:creator>
      <dc:date>2023-11-28T06:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction for error message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-for-error-message/m-p/669980#M229723</link>
      <description>&lt;P&gt;What defines the start and end of the error text in each of those examples and how much of that do you want to get in error_message&lt;/P&gt;&lt;P&gt;You could very simply do this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\]:\s(?&amp;lt;error_message&amp;gt;.*)"&lt;/LI-CODE&gt;&lt;P&gt;which would take everything after the ]: to the end of the event&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 07:59:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/field-extraction-for-error-message/m-p/669980#M229723</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-11-28T07:59:47Z</dc:date>
    </item>
  </channel>
</rss>

