<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why some Fields are extracted and some are not in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18053#M2577</link>
    <description>&lt;P&gt;it extract some values under _serial field, even though it is not there in transforms.conf.&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2011 06:05:02 GMT</pubDate>
    <dc:creator>tkadale</dc:creator>
    <dc:date>2011-05-31T06:05:02Z</dc:date>
    <item>
      <title>Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18048#M2572</link>
      <description>&lt;P&gt;I have indexed memory log files for windows. I have done the required the configuration in props.conf and transforms.conf. but only few fields are extracted and few are not. How does it happen. Either it should extract all fields or none. &lt;BR /&gt;
Can anybody help??&lt;BR /&gt;
Thanks in Advance. &lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2011 05:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18048#M2572</guid>
      <dc:creator>tkadale</dc:creator>
      <dc:date>2011-05-27T05:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18049#M2573</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;my suggestion is to use REGEX tool to test your extract rule first ( if you are using "EXTRACT-" or "REPORT-" to extract field).&lt;/P&gt;

&lt;P&gt;or you can share your props.conf , transforms.conf and some sample events , we can take a look .&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2011 09:44:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18049#M2573</guid>
      <dc:creator>dmlee</dc:creator>
      <dc:date>2011-05-27T09:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18050#M2574</link>
      <description>&lt;P&gt;Here is my props.conf stanza's&lt;BR /&gt;
[source::...&lt;EM&gt;NT_Memory&lt;/EM&gt;...]&lt;BR /&gt;
sourcetype = win-memory&lt;BR /&gt;
TRANSFORMS-null= setnull&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18050#M2574</guid>
      <dc:creator>tkadale</dc:creator>
      <dc:date>2020-09-28T09:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18051#M2575</link>
      <description>&lt;P&gt;[win-memory]&lt;BR /&gt;
REPORT-win-memory=argus_extractions_win_memory&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18051#M2575</guid>
      <dc:creator>tkadale</dc:creator>
      <dc:date>2020-09-28T09:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18052#M2576</link>
      <description>&lt;P&gt;Then in transforms.conf I have mentioned the fields:&lt;BR /&gt;
[argus_extractions_win_memory]&lt;BR /&gt;
DELIMS=","&lt;BR /&gt;
FIELDS = Here are around 25 fields.&lt;BR /&gt;
Only first 10 fields are extracted.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18052#M2576</guid>
      <dc:creator>tkadale</dc:creator>
      <dc:date>2020-09-28T09:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18053#M2577</link>
      <description>&lt;P&gt;it extract some values under _serial field, even though it is not there in transforms.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2011 06:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18053#M2577</guid>
      <dc:creator>tkadale</dc:creator>
      <dc:date>2011-05-31T06:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why some Fields are extracted and some are not</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18054#M2578</link>
      <description>&lt;P&gt;Hi, did you ever find a resolution to this? I am experiencing the same phenomenom in splunk 5.0.1. Some fields are being extracted properly and sometimes they are not (the same fields I mean!) Very strange.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2013 15:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-some-Fields-are-extracted-and-some-are-not/m-p/18054#M2578</guid>
      <dc:creator>srowe</dc:creator>
      <dc:date>2013-03-27T15:39:10Z</dc:date>
    </item>
  </channel>
</rss>

