<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field Extraction index=_internal in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701422#M237928</link>
    <description>&lt;P&gt;I've tried to search internal in several different apps and it all extracted the fields.&amp;nbsp; The field extractions are clearly marked out in props.conf under the Splun app default directory.&amp;nbsp; I really can't see how that would have been subverted but a btool outputs from props.conf for stanza splunkd would be good.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2024 13:37:37 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-10-09T13:37:37Z</dc:date>
    <item>
      <title>Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701418#M237925</link>
      <description>&lt;P&gt;I tried to run the&amp;nbsp;Indexing Performance: Instance dashboard but was not getting any data, on exploring the search I found out index=_internal is not doing the field extractions for this data in the log:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;group=per_host_thruput, ingest_pipe=1, series="splunkserver.local", kbps=8.451, eps=32.903, kb=261.974, ev=1020, avg_age=2.716, max_age=3	&lt;/LI-CODE&gt;&lt;P&gt;If I manually extract the fields using rex I can view it in the search but the dashboard still doesn't show the results. Is there a way to extract these fields for the internal index?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 12:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701418#M237925</guid>
      <dc:creator>geekf</dc:creator>
      <dc:date>2024-10-09T12:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701422#M237928</link>
      <description>&lt;P&gt;I've tried to search internal in several different apps and it all extracted the fields.&amp;nbsp; The field extractions are clearly marked out in props.conf under the Splun app default directory.&amp;nbsp; I really can't see how that would have been subverted but a btool outputs from props.conf for stanza splunkd would be good.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 13:37:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701422#M237928</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-10-09T13:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701425#M237929</link>
      <description>&lt;P&gt;Thank you for your response. I am uploading the btool output for splunkd.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 13:56:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701425#M237929</guid>
      <dc:creator>geekf</dc:creator>
      <dc:date>2024-10-09T13:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701435#M237932</link>
      <description>&lt;P&gt;I can't really see anything wrong but I dislike the following.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/etc/system/local/props.conf     KV_MODE = json&lt;/LI-CODE&gt;&lt;P&gt;Since I do see it in several of the various splunkd* stanzas it makes me think it was set in local under a default stanza.&amp;nbsp; I personally would look to remove that but keep in mind if this fixes the internal log extraction it will break something else that needs the json configuration.&amp;nbsp; I've always tried to create custom apps and place any default overrides in the custom app rather than allow anything to fall into the ./splunk/etc/system/local/*.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 14:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/701435#M237932</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-10-09T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/702594#M238216</link>
      <description>&lt;P&gt;We use json for Zeek, if we change that setting, will it impact Zeek logs?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:45:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/702594#M238216</guid>
      <dc:creator>geekf</dc:creator>
      <dc:date>2024-10-23T12:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/702597#M238217</link>
      <description>&lt;P&gt;If you put that setting under the specific stanza for that sourcetype then changes to default stanza wont impact.&amp;nbsp; Anything under default stanza is only considered if the same setting has NOT been set in a more specific stanza.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/702597#M238217</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-10-23T12:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction index=_internal</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/702604#M238221</link>
      <description>&lt;P&gt;We made this change, and it worked fine!&lt;/P&gt;&lt;P&gt;Thank you so much for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 13:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-index-internal/m-p/702604#M238221</guid>
      <dc:creator>geekf</dc:creator>
      <dc:date>2024-10-23T13:52:08Z</dc:date>
    </item>
  </channel>
</rss>

