<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regarding autoextraction of Fields in Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204107#M59296</link>
    <description>&lt;P&gt;I am running the same query.&lt;/P&gt;

&lt;P&gt;Resolved the issue:&lt;/P&gt;

&lt;P&gt;Issue: Autoextraction was not working.&lt;/P&gt;

&lt;P&gt;Workaround :  Tried extracting the fields using regular expression and was able to extract the same&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jan 2016 09:03:20 GMT</pubDate>
    <dc:creator>pradiptam</dc:creator>
    <dc:date>2016-01-01T09:03:20Z</dc:date>
    <item>
      <title>Regarding autoextraction of Fields in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204105#M59294</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I was able to run search queries in Splunk and the fields were getting automatically extracted in the Interesting Fields and depending upon that we were able to modify queries.&lt;/P&gt;

&lt;P&gt;But currently i am able to run the queries and getting results, but the fields are not getting listed under the "  Interesting Fields ".  &lt;/P&gt;

&lt;P&gt;I am not able to figure out the issue, is any settings have changed or not?   Please share some thoughts on the same.&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Pradipta&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2016 07:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204105#M59294</guid>
      <dc:creator>pradiptam</dc:creator>
      <dc:date>2016-01-01T07:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding autoextraction of Fields in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204106#M59295</link>
      <description>&lt;P&gt;Is that you are running the same query as used before or anything else?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2016 07:48:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204106#M59295</guid>
      <dc:creator>kamaleshwar</dc:creator>
      <dc:date>2016-01-01T07:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding autoextraction of Fields in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204107#M59296</link>
      <description>&lt;P&gt;I am running the same query.&lt;/P&gt;

&lt;P&gt;Resolved the issue:&lt;/P&gt;

&lt;P&gt;Issue: Autoextraction was not working.&lt;/P&gt;

&lt;P&gt;Workaround :  Tried extracting the fields using regular expression and was able to extract the same&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2016 09:03:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204107#M59296</guid>
      <dc:creator>pradiptam</dc:creator>
      <dc:date>2016-01-01T09:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding autoextraction of Fields in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204108#M59297</link>
      <description>&lt;P&gt;If you were able to see the fields before and not now, then most probably it's due to different search mode unless your raw events are changed.&lt;/P&gt;

&lt;P&gt;See here for information : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Search/Changethesearchmode"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Search/Changethesearchmode&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2016 09:29:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regarding-autoextraction-of-Fields-in-Splunk/m-p/204108#M59297</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-01-01T09:29:15Z</dc:date>
    </item>
  </channel>
</rss>

