<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I search using field components? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96522#M24937</link>
    <description>&lt;P&gt;The solution described using that link worked. Thanks for the quick response.&lt;/P&gt;

&lt;P&gt;I am using a fresh install of 4.3.1. I can move fields.conf out of the way and rerun a search and it will fail, so clearly the issue still exists with 4.3.1, with the same solution.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Mar 2012 17:24:40 GMT</pubDate>
    <dc:creator>steveta_uk</dc:creator>
    <dc:date>2012-03-19T17:24:40Z</dc:date>
    <item>
      <title>How do I search using field components?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96520#M24935</link>
      <description>&lt;P&gt;I'm a newbie to Splunk, and I'm having difficulty with field definitions and searches.&lt;/P&gt;

&lt;P&gt;My input data (from syslog) contains one field of a form such as ":ABC1234I:" which means component "ABC" generate log message ID 1234 at level I (info). This is parsed fairly easily using this REGEX:&lt;/P&gt;

&lt;P&gt;(?i):(?P&lt;LOGGER&gt;[A-Z][A-Z][A-Z])(?P&lt;LOGNO&gt;[\d][\d][\d][\d])(?P&lt;SEV&gt;[DWIEF]):&lt;/SEV&gt;&lt;/LOGNO&gt;&lt;/LOGGER&gt;&lt;/P&gt;

&lt;P&gt;The search shows Logger, Logno, and Sev under "interesting fields" as expected, and shows the set of values found for each one. All this seems fine.&lt;/P&gt;

&lt;P&gt;But when I select one of the values under "Logger", I get no matches, despite it already listing some 26,000+ hits for that particular value.&lt;/P&gt;

&lt;P&gt;The search term in this instance is &lt;/P&gt;

&lt;P&gt;sourcetype="syslog" Logger="CGP"&lt;/P&gt;

&lt;P&gt;What am I doing wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2012 16:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96520#M24935</guid>
      <dc:creator>steveta_uk</dc:creator>
      <dc:date>2012-03-19T16:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search using field components?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96521#M24936</link>
      <description>&lt;P&gt;What version of Splunk are you running? Your problem sounds very much like what is described here: &lt;A href="http://blogs.splunk.com/2011/10/07/cannot-search-based-on-an-extracted-field/"&gt;http://blogs.splunk.com/2011/10/07/cannot-search-based-on-an-extracted-field/&lt;/A&gt;&lt;BR /&gt;
But it's supposed to be fixed in 4.3.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2012 17:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96521#M24936</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-03-19T17:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search using field components?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96522#M24937</link>
      <description>&lt;P&gt;The solution described using that link worked. Thanks for the quick response.&lt;/P&gt;

&lt;P&gt;I am using a fresh install of 4.3.1. I can move fields.conf out of the way and rerun a search and it will fail, so clearly the issue still exists with 4.3.1, with the same solution.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2012 17:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96522#M24937</guid>
      <dc:creator>steveta_uk</dc:creator>
      <dc:date>2012-03-19T17:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search using field components?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96523#M24938</link>
      <description>&lt;P&gt;Interesting. Something for the Splunk people to have a look at. If your issue is solved, could you mark my answer as accepted? Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2012 20:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-using-field-components/m-p/96523#M24938</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-03-19T20:05:30Z</dc:date>
    </item>
  </channel>
</rss>

