<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are fields not being extracted for some events with no apparent pattern? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113771#M30008</link>
    <description>&lt;P&gt;So now I'm getting partially extracted data where some fields are always pulled but the durations in nanos are sometimes not getting pulled out (based on a cursory look)&lt;/P&gt;</description>
    <pubDate>Fri, 05 Sep 2014 19:39:39 GMT</pubDate>
    <dc:creator>jmwatson</dc:creator>
    <dc:date>2014-09-05T19:39:39Z</dc:date>
    <item>
      <title>Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113767#M30004</link>
      <description>&lt;P&gt;We are not getting extracted fields for some events and there's no apparent pattern as to why.  These are all simple extractions and they usually work.  This is very problematic as will result in false statistics.&lt;/P&gt;

&lt;P&gt;Extracted:&lt;/P&gt;

&lt;P&gt;2014-09-03T10:59:59.316-0400 myAction="CachePut" myActualContext="services.ServiceService" myCacheType="remote" myDurationNanos="2209789" myRecordedTimestamp="2014/09/03 10:59:59.316 EDT" myRequestedContext="services.MemberGetSystemMap" {myUow=c17df9e5-1261-4d2d-907a-12ca954ce11f}&lt;/P&gt;

&lt;P&gt;2014-09-03T10:59:59.224-0400 ihAction="CachePut" myActualContext="null" myCacheType="local" myDurationNanos="426969" myRecordedTimestamp="2014/09/03 10:59:59.224 EDT" myRequestedContext="Sxc.getMemberEffectiveDates" {myUow=c17df9e5-1261-4d2d-907a-12ca954ce11f}&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Not&lt;/STRONG&gt; Extracted:&lt;/P&gt;

&lt;P&gt;2014-09-03T10:59:59.264-0400 myAction="CachePut" myActualContext="null" myCacheType="remote" myDurationNanos="2293969" myRecordedTimestamp="2014/09/03 10:59:59.264 EDT" myRequestedContext="Power.getMemberEffectiveDates" {myUow=fadcb445-3722-4289-8821-04c6874942e5}&lt;/P&gt;

&lt;P&gt;Is this a known bug and/or is there a way we can get debug why the extraction is not occurring for some events?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 18:13:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113767#M30004</guid>
      <dc:creator>jmwatson</dc:creator>
      <dc:date>2014-09-05T18:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113768#M30005</link>
      <description>&lt;P&gt;I do not know the answer to your problem but here are some questions that might help: Did you set up any manual extractions (using props &amp;amp; transforms)? Are none of the fields extracted or only some? All the events have the same sourcetype right? If not does splunk btool props list  display KV_MODE=none for one sourcetype? There aren't any unescaped or extra " in there  events that do not work,right (I do not see any in your sample)? Does adding a "| extract " to the end of your search change anything?&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Extract"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Extract&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 19:06:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113768#M30005</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2014-09-05T19:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113769#M30006</link>
      <description>&lt;OL&gt;
&lt;LI&gt;manual extractions:  I don't think so but I need to confirm with a colleague.&lt;/LI&gt;
&lt;LI&gt;none or some: when it works, all are extracted, when it doesn't none are&lt;/LI&gt;
&lt;LI&gt;same sourcetype: yes&lt;/LI&gt;
&lt;LI&gt;any unescaped or extra ": not that I can see, examples are copied from splunk raw value.&lt;/LI&gt;
&lt;LI&gt;btool props list display KV_MODE=none: over my head, need to phone a friend&lt;/LI&gt;
&lt;LI&gt;adding a "| extract " to the end: Hey, that seems do the trick.  Excellent!  Does that indicate what the problem is?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 05 Sep 2014 19:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113769#M30006</guid>
      <dc:creator>jmwatson</dc:creator>
      <dc:date>2014-09-05T19:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113770#M30007</link>
      <description>&lt;P&gt;Almost forgot: Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 19:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113770#M30007</guid>
      <dc:creator>jmwatson</dc:creator>
      <dc:date>2014-09-05T19:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113771#M30008</link>
      <description>&lt;P&gt;So now I'm getting partially extracted data where some fields are always pulled but the durations in nanos are sometimes not getting pulled out (based on a cursory look)&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 19:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113771#M30008</guid>
      <dc:creator>jmwatson</dc:creator>
      <dc:date>2014-09-05T19:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113772#M30009</link>
      <description>&lt;P&gt;Update: Although telling the search to extract (what I think it's always supposed to do anyway) seemed to help, I've found more examples where this doesn't have any effect and no fields are being extracted from events similar to those shown above.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 20:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113772#M30009</guid>
      <dc:creator>jmwatson</dc:creator>
      <dc:date>2014-09-05T20:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113773#M30010</link>
      <description>&lt;P&gt;I still do not see what is not working with your events. If you do not know if you have any manual field extractions configured you probably don't have any. I have encountered sourcetypes where Splunk did not work in 100% of the cases. What I usually do then is switch to  a manually configured extraction.&lt;/P&gt;

&lt;P&gt;If you do not know about props &amp;amp; transforms yet -&amp;gt; &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles"&gt;read this documentation&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There is a GUI field extractor that might help -&amp;gt; &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/ExtractfieldsinteractivelywithIFX"&gt;documented here&lt;/A&gt; I don't use it so I can't tell if it will work for your problem &lt;/P&gt;

&lt;P&gt;If you have access to the file system of your Splunk server you can either create or add the following stanzas to props.conf &amp;amp; transforms.conf in &lt;SPLUNKINSTALLATIONDIRECTORY&gt;/etc/system/local&lt;/SPLUNKINSTALLATIONDIRECTORY&gt;&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[replaceWithYourSourcetype]
KV_MODE=none
REPORT-test=delims
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[delims]
DELIMS = " ", "="
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 05 Sep 2014 21:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113773#M30010</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2014-09-05T21:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are fields not being extracted for some events with no apparent pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113774#M30011</link>
      <description>&lt;P&gt;I guess this is the best answer I will get for this.  I appreciate your help but frankly it leaves me a little cold.  I'm pretty new to Splunk.  Is it typical to see things not really work right and you are on your own to work around it?  I'm not accustomed to this approach with paid software (IBM aside.)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2014 14:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-fields-not-being-extracted-for-some-events-with-no/m-p/113774#M30011</guid>
      <dc:creator>jmwatson</dc:creator>
      <dc:date>2014-09-08T14:18:44Z</dc:date>
    </item>
  </channel>
</rss>

