<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with fields extractions using configuration files in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146991#M41077</link>
    <description>&lt;P&gt;Has anything changes in the logs events since yesterday? Validate if the field extractions are still valid (try with search manually). Since it was working till yesterday, I am assuming sharing permissions are still good.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jul 2014 12:33:20 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-07-17T12:33:20Z</dc:date>
    <item>
      <title>Problem with fields extractions using configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146990#M41076</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I'm creating an add-on that sets a data source and fields extractions.&lt;BR /&gt;
First, I modify inputs.conf to set the UDP port. Then, using props.conf and tranforms.conf, I perform the field extractions. When I check on the web platform, (Manage -&amp;gt; Fields -&amp;gt; select the app) I can clearly see the list of fields. However, running the search none of the fields has been extracted.&lt;/P&gt;

&lt;P&gt;Please note that I've restarted the splunk instance to apply changes, double checked the name of the config files. Plus, everything was working perfectly yesterday.&lt;/P&gt;

&lt;P&gt;Please is there anyone who can help,&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 12:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146990#M41076</guid>
      <dc:creator>SalimRahmani</dc:creator>
      <dc:date>2014-07-17T12:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with fields extractions using configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146991#M41077</link>
      <description>&lt;P&gt;Has anything changes in the logs events since yesterday? Validate if the field extractions are still valid (try with search manually). Since it was working till yesterday, I am assuming sharing permissions are still good.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 12:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146991#M41077</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-17T12:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with fields extractions using configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146992#M41078</link>
      <description>&lt;P&gt;actually can you tell me which log file to look in ?!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 13:14:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146992#M41078</guid>
      <dc:creator>SalimRahmani</dc:creator>
      <dc:date>2014-07-17T13:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with fields extractions using configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146993#M41079</link>
      <description>&lt;P&gt;You can see the field extraction logic( defined in props.conf and/or transforms.conf) from the Splunk Web, right? Just take the regex's and test them if they still work (in case the data got changed and due to which they might not be working).&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 13:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146993#M41079</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-17T13:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with fields extractions using configuration files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146994#M41080</link>
      <description>&lt;P&gt;Sorry buddy, I found the problem. It was a referencing problem between props.conf and transforms.conf ! Yeah sometimes I'm dumb haha! though I appreciate your help!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 15:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-fields-extractions-using-configuration-files/m-p/146994#M41080</guid>
      <dc:creator>SalimRahmani</dc:creator>
      <dc:date>2014-07-17T15:36:10Z</dc:date>
    </item>
  </channel>
</rss>

