<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field Extractions not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157860#M44471</link>
    <description>&lt;P&gt;please provide a sample of the events to verify the rex.&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2014 22:39:48 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2014-05-08T22:39:48Z</dc:date>
    <item>
      <title>Field Extractions not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157859#M44470</link>
      <description>&lt;P&gt;I'm trying to get field extractions to show up in the Interesting Fields.&lt;/P&gt;

&lt;P&gt;My search string is as follows, and it completes successfully:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=syslog rgw01.lab | rex field=_raw "%SEC-6-IPACCESSLOG.?.:  list (?P&amp;lt;log_acl_name&amp;gt;[A-Z]+\:[A-Z]+\:[A-Z]+) \w+ (?P&amp;lt;log_acl_proto&amp;gt;\w+) (?P&amp;lt;log_acl_sip&amp;gt;[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3})([(][0-9]+[)] |[ ])-&amp;gt; (?P&amp;lt;log_acl_dip&amp;gt;[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3})(?P&amp;lt;log_acl_dport&amp;gt;[(][0-9]+[)][,]|[,])"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I would expect these field extractions to show up, but they do not:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;log_acl_name
log_acl_proto
log_acl_sip
log_acl_dip
log_acl_dport
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried adding this to Settings &amp;gt; Fields &amp;gt; Field Extractions, but it still doesn't show up:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"%SEC-6-IPACCESSLOG.?.:  list (?P&amp;lt;log_acl_name&amp;gt;[A-Z]+\:[A-Z]+\:[A-Z]+) \w+ (?P&amp;lt;log_acl_proto&amp;gt;\w+) (?P&amp;lt;log_acl_sip&amp;gt;[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3})([(][0-9]+[)] |[ ])-&amp;gt; (?P&amp;lt;log_acl_dip&amp;gt;[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3})(?P&amp;lt;log_acl_dport&amp;gt;[(][0-9]+[)][,]|[,])"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I ran this regex through &lt;A href="http://www.regexr.com"&gt;www.regexr.com&lt;/A&gt; and it matched everything I was interested in, so I used that as a template to construct the rex:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; %SEC-6-IPACCESSLOG.?.: list [A-Z]+\:[A-Z]+\:[A-Z]+ \w+ \w+ ([\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3})([(][0-9]+[)] |[ ])-&amp;gt; ([\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3})([(][0-9]+[)][,]|[,])
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here's some sample events:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2014-05-08T11:12:45.910030-04:00 lo21949.rgw01.lab.beanfield.com 193207: rgw01.lab: May  8 11:11:54.420: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.188(37548) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:12:35.937906-04:00 lo21949.rgw01.lab.beanfield.com 193206: rgw01.lab: May  8 11:11:44.448: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.191 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:12:34.843132-04:00 lo21949.rgw01.lab.beanfield.com 193205: rgw01.lab: May  8 11:11:43.350: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.228(55094) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:12:33.806361-04:00 lo21949.rgw01.lab.beanfield.com 193204: rgw01.lab: May  8 11:11:42.316: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.238 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:12:28.053939-04:00 lo21949.rgw01.lab.beanfield.com 193203: rgw01.lab: May  8 11:11:36.561: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.191(53347) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:12:07.076675-04:00 lo21949.rgw01.lab.beanfield.com 193201: rgw01.lab: May  8 11:11:15.584: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.223(58230) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:12:02.141604-04:00 lo21949.rgw01.lab.beanfield.com 193200: rgw01.lab: May  8 11:11:10.649: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.190(46180) -&amp;gt; 172.16.0.4(80), 1 packet
2014-05-08T11:11:53.415260-04:00 lo21949.rgw01.lab.beanfield.com 193199: rgw01.lab: May  8 11:11:01.922: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.238(35810) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:11:37.322462-04:00 lo21949.rgw01.lab.beanfield.com 193198: rgw01.lab: May  8 11:10:45.833: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.249 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:11:36.274565-04:00 lo21949.rgw01.lab.beanfield.com 193197: rgw01.lab: May  8 11:10:44.784: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.191 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:11:35.038938-04:00 lo21949.rgw01.lab.beanfield.com 193196: rgw01.lab: May  8 11:10:43.548: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.228(55093) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:11:32.034399-04:00 lo21949.rgw01.lab.beanfield.com 193195: rgw01.lab: May  8 11:10:40.544: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.190 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:11:29.210428-04:00 lo21949.rgw01.lab.beanfield.com 193194: rgw01.lab: May  8 11:10:37.719: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.248(46516) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:11:21.422505-04:00 lo21949.rgw01.lab.beanfield.com 193193: rgw01.lab: May  8 11:10:29.929: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.249(59616) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:11:04.257287-04:00 lo21949.rgw01.lab.beanfield.com 193191: rgw01.lab: May  8 11:10:12.767: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.190(46178) -&amp;gt; 172.16.0.4(80), 1 packet
2014-05-08T11:10:53.425363-04:00 lo21949.rgw01.lab.beanfield.com 193190: rgw01.lab: May  8 11:10:01.935: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.238(35809) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:10:45.705140-04:00 lo21949.rgw01.lab.beanfield.com 193189: rgw01.lab: May  8 11:09:54.214: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.188(37544) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:10:36.785036-04:00 lo21949.rgw01.lab.beanfield.com 193188: rgw01.lab: May  8 11:09:45.295: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.188 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:10:35.457510-04:00 lo21949.rgw01.lab.beanfield.com 193187: rgw01.lab: May  8 11:09:43.969: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.191 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:10:32.421042-04:00 lo21949.rgw01.lab.beanfield.com 193185: rgw01.lab: May  8 11:09:40.929: %SEC-6-IPACCESSLOGRP: list FILTER:TV:IN permitted igmp 172.23.255.249 -&amp;gt; 224.0.0.22, 1 packet
2014-05-08T11:10:29.186012-04:00 lo21949.rgw01.lab.beanfield.com 193184: rgw01.lab: May  8 11:09:37.695: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.248(46514) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:10:28.054410-04:00 lo21949.rgw01.lab.beanfield.com 193183: rgw01.lab: May  8 11:09:36.561: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.191(53344) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:10:21.628942-04:00 lo21949.rgw01.lab.beanfield.com 193182: rgw01.lab: May  8 11:09:30.139: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.249(59613) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:10:16.498384-04:00 lo21949.rgw01.lab.beanfield.com 193181: rgw01.lab: May  8 11:09:25.008: %SEC-6-IPACCESSLOGP: list FILTER:TV:OUT permitted udp 172.16.5.4(50904) -&amp;gt; 232.16.2.17(2017), 600 packets
2014-05-08T11:10:16.498182-04:00 lo21949.rgw01.lab.beanfield.com 193180: rgw01.lab: May  8 11:09:25.008: %SEC-6-IPACCESSLOGP: list FILTER:TV:OUT permitted udp 172.16.5.15(34829) -&amp;gt; 232.16.2.160(2160), 600 packets
2014-05-08T11:10:06.881113-04:00 lo21949.rgw01.lab.beanfield.com 193178: rgw01.lab: May  8 11:09:15.390: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.223(58228) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:10:04.478482-04:00 lo21949.rgw01.lab.beanfield.com 193177: rgw01.lab: May  8 11:09:12.987: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.190(46177) -&amp;gt; 172.16.0.4(80), 1 packet
2014-05-08T11:09:51.405301-04:00 lo21949.rgw01.lab.beanfield.com 193176: rgw01.lab: May  8 11:08:59.914: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.249(59611) -&amp;gt; 172.16.0.2(80), 1 packet
2014-05-08T11:09:45.901948-04:00 lo21949.rgw01.lab.beanfield.com 193175: rgw01.lab: May  8 11:08:54.412: %SEC-6-IPACCESSLOGP: list FILTER:TV:IN permitted tcp 172.23.255.188(37543) -&amp;gt; 172.16.0.2(80), 1 packet
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm not sure what else I might need to do...  Any advice?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 21:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157859#M44470</guid>
      <dc:creator>jlixfeld</dc:creator>
      <dc:date>2014-05-08T21:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157860#M44471</link>
      <description>&lt;P&gt;please provide a sample of the events to verify the rex.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 22:39:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157860#M44471</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-05-08T22:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157861#M44472</link>
      <description>&lt;P&gt;Thanks.  Original post updated to include sample data.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2014 13:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157861#M44472</guid>
      <dc:creator>jlixfeld</dc:creator>
      <dc:date>2014-05-09T13:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157862#M44473</link>
      <description>&lt;P&gt;I see there is an extra space in your regex before word 'list'. I just removed it and your regex expression worked for your sample logs.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2014 14:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157862#M44473</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-05-09T14:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extractions not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157863#M44474</link>
      <description>&lt;P&gt;Son of a ...  Damn, how careless of me.  Thanks, seems to work now.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2014 14:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extractions-not-working/m-p/157863#M44474</guid>
      <dc:creator>jlixfeld</dc:creator>
      <dc:date>2014-05-09T14:21:29Z</dc:date>
    </item>
  </channel>
</rss>

