<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180327#M51916</link>
    <description>&lt;P&gt;Checked &lt;CODE&gt;_internal&lt;/CODE&gt; for errors?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2015 19:54:20 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-08-18T19:54:20Z</dc:date>
    <item>
      <title>Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180324#M51913</link>
      <description>&lt;P&gt;I have some logs from a media server that are all formatted in a consistent way, making field extraction creation very easy.  I have created the same group of field extractions numerous times because they stop working within 24hrs even without any change in the format of the logs.  I have looked at properly tagged events and I have looked at the logs that were not properly tagged and they are identical.  There is no reason that I can think of for these field extractions to only work for a short amount of time.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180324#M51913</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-18T19:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180325#M51914</link>
      <description>&lt;P&gt;Does the field extraction config disappear?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180325#M51914</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-08-18T19:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180326#M51915</link>
      <description>&lt;P&gt;No.  It remains and is unchanged.  Also, the logs that come in after the extraction stops working are in exactly the same format.  There are no missing fields or anything that would throw off the extraction.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180326#M51915</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-18T19:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180327#M51916</link>
      <description>&lt;P&gt;Checked &lt;CODE&gt;_internal&lt;/CODE&gt; for errors?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:54:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180327#M51916</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-08-18T19:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180328#M51917</link>
      <description>&lt;P&gt;I don't see anything in _internal that seems to relate.  &lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 20:49:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180328#M51917</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-18T20:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180329#M51918</link>
      <description>&lt;P&gt;You mentioned re-creating the extractions - how, where?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 21:40:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180329#M51918</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-08-18T21:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180330#M51919</link>
      <description>&lt;P&gt;Are you defining extractions against sourcetype or source? Are you able to provide the configuration you have defined in your props.conf?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 02:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180330#M51919</guid>
      <dc:creator>sajbutler</dc:creator>
      <dc:date>2015-08-19T02:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180331#M51920</link>
      <description>&lt;P&gt;I used the tool create the field extractions.  By recreating, I mean that I delete the extraction and build again.  It works for a day and then just stops working.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 11:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180331#M51920</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-19T11:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180332#M51921</link>
      <description>&lt;P&gt;I built against the source type using the field extraction tool in the web GUI.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 11:51:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180332#M51921</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-19T11:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180333#M51922</link>
      <description>&lt;P&gt;Do extractions work for events older than 24 hours? Or do they just not work at all for any event, no matter their timestamp?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 11:55:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180333#M51922</guid>
      <dc:creator>sajbutler</dc:creator>
      <dc:date>2015-08-19T11:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180334#M51923</link>
      <description>&lt;P&gt;Example of logs that did NOT extract properly:&lt;BR /&gt;
Mon Aug 17 00:14:14 2015: pvols1979 Watched: CSI: Crime Scene Investigation - Gum Drops - s06e05 [T] [2005] [TV-14] on Roku 3 for 48 minutes [100%] 192.168.1.175&lt;BR /&gt;
Sat Aug 15 22:21:14 2015: Amy Watched: NCIS: New Orleans - The List - s01e18 [T] [2015] [TV-PG] on Roku 2 XS for 42 minutes [100%] 192.168.1.134&lt;/P&gt;

&lt;P&gt;Examples of logs that did extract properly:&lt;BR /&gt;
Sat Aug 15 21:29:14 2015: Amy Watched: Rizzoli &amp;amp; Isles - Nice to Meet You, Dr. Isles - s06e08 [T] [2015] [TV-14] on Roku 2 XS for 42 minutes [100%] 192.168.1.134&lt;BR /&gt;
Sat Aug 15 20:44:14 2015: Amy Watched: Rizzoli &amp;amp; Isles - A Bad Seed Grows - s06e07 [T] [2015] [TV-14] on Roku 2 XS for 42 minutes [100%] 192.168.1.134&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 11:56:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180334#M51923</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-19T11:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180335#M51924</link>
      <description>&lt;P&gt;They appear to only work for extractions that are older and not recent.  I imagine that might be an issue with my regex, but I don't know exactly what is off.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 11:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180335#M51924</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-19T11:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180336#M51925</link>
      <description>&lt;P&gt;pms_watched : EXTRACT-user,title,transcode,release_year,content_rating,player,play_length,watched_percentage,client_ip&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^(?:[^:\n]*:){3}\s+(?P&amp;lt;user&amp;gt;[^ ]+) Watched: (?P&amp;lt;title&amp;gt;[^\[]+)\[(?P&amp;lt;transcode&amp;gt;\w+)[^ \n]* \[(?P&amp;lt;release_year&amp;gt;[^\]]+)[^ \n]* \[(?P&amp;lt;content_rating&amp;gt;\w+\-\d+)\]\s+\w+\s+(?P&amp;lt;player&amp;gt;\w+\s+\d+\s+\w+)\s+\w+\s+(?P&amp;lt;play_length&amp;gt;\d+\s+[a-z]+\s+)\[(?P&amp;lt;watched_percentage&amp;gt;\d+%)\]\s+(?P&amp;lt;client_ip&amp;gt;.+)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180336#M51925</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2020-09-29T07:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180337#M51926</link>
      <description>&lt;P&gt;Does the sourcetype name remain the same for events over time? That is, is the sourcename for events that occur today (when extraction is &lt;EM&gt;not&lt;/EM&gt; working) the same as the sourcename of events that occur yesterdau (when extraction is working)&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 12:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180337#M51926</guid>
      <dc:creator>sajbutler</dc:creator>
      <dc:date>2015-08-19T12:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180338#M51927</link>
      <description>&lt;P&gt;Yes.  The source type and the source name both remain the same.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 12:04:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180338#M51927</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-19T12:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180339#M51928</link>
      <description>&lt;P&gt;Hmmmm. The only other suggestion I can make (other than getting a sample of the data and the REGEX you are using and helping debug, which I am happy help with BTW) is to ask about &lt;EM&gt;where&lt;/EM&gt; the extractions are being stored. Specifically, are they in the props.conf of the app in which you are executing the search?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 12:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180339#M51928</guid>
      <dc:creator>sajbutler</dc:creator>
      <dc:date>2015-08-19T12:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180340#M51929</link>
      <description>&lt;P&gt;The field extraction is applied only to the search app.  I am playing around with a regex tester online to see if I can figure out why the ones that don't work are messed up.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 13:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180340#M51929</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-19T13:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180341#M51930</link>
      <description>&lt;P&gt;Looking at your example, you have this in your regex:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(?P&amp;lt;player&amp;gt;\w+\s+\d+\s+\w+)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, your events have either &lt;CODE&gt;Roku 3&lt;/CODE&gt; or &lt;CODE&gt;Roku 2 XS&lt;/CODE&gt; for the &lt;CODE&gt;player&lt;/CODE&gt; field - this regex matches the 2 XS, but not the 3 for lack of a third word.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 17:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180341#M51930</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-08-19T17:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180342#M51931</link>
      <description>&lt;P&gt;Very good.  Thanks.  I noticed there were a couple more regex issues as well.  Evidently, when you do multiple extractions in one rule with the field extractions tool, they all have to be accurate or none of them work individually.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 10:32:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180342#M51931</guid>
      <dc:creator>pwilliams_splun</dc:creator>
      <dc:date>2015-08-20T10:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why are field extractions only working for 24 hours or less if the log format hasn't changed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180343#M51932</link>
      <description>&lt;P&gt;That is expected behaviour, a regex can only extract fields if it matches the string.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 11:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-field-extractions-only-working-for-24-hours-or-less-if/m-p/180343#M51932</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-08-20T11:19:45Z</dc:date>
    </item>
  </channel>
</rss>

