<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatically extracting field at search time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29523#M5960</link>
    <description>&lt;P&gt;If the IFX creates an invalid extraction you can just specify your own regex that you know works.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jun 2011 21:31:07 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-06-20T21:31:07Z</dc:date>
    <item>
      <title>Automatically extracting field at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29518#M5955</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Previously I was searching and extracting field at search time by explicitly specifying &lt;CODE&gt;rex&lt;/CODE&gt; command. Now, I want to do the same thing but I want splunk to understand that I want "that" field extracted when relevant data is searched. How can I do using manager? ( Also, I do wish to keep it general i.e. not based on any source or something similar. )&lt;/P&gt;

&lt;P&gt;My previous query was -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;* | rex "(?&amp;lt;authentication_type&amp;gt;(?i)(password))"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now, I want to do something like this -&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;* authentication_type=password&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Thanks, &lt;BR /&gt;
Rahil&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2011 17:52:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29518#M5955</guid>
      <dc:creator>rahiparikh</dc:creator>
      <dc:date>2011-06-16T17:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically extracting field at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29519#M5956</link>
      <description>&lt;P&gt;Manager -&amp;gt; Fields -&amp;gt; Field Extractions&lt;/P&gt;

&lt;P&gt;You can basically paste a rex regex into the new extraction.  However, an extraction must target a source, sourcetype, or host.  I suppose you could set the source value to "*" though.&lt;/P&gt;

&lt;P&gt;Reading up on props.conf will give you some insight into this: &lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Propsconf"&gt;http://www.splunk.com/base/Documentation/latest/admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2011 21:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29519#M5956</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-06-16T21:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically extracting field at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29520#M5957</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Thanks for the reply. I am unable to extract the field the way you specified using Manager.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2011 15:21:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29520#M5957</guid>
      <dc:creator>rahiparikh</dc:creator>
      <dc:date>2011-06-20T15:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically extracting field at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29521#M5958</link>
      <description>&lt;P&gt;Use the interactive field extractor.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/User/InteractiveFieldExtractionExample"&gt;http://www.splunk.com/base/Documentation/latest/User/InteractiveFieldExtractionExample&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2011 21:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29521#M5958</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-06-20T21:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically extracting field at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29522#M5959</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I already tried that but in IFE it extracts some not required results. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Though.. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2011 21:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29522#M5959</guid>
      <dc:creator>rahiparikh</dc:creator>
      <dc:date>2011-06-20T21:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically extracting field at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29523#M5960</link>
      <description>&lt;P&gt;If the IFX creates an invalid extraction you can just specify your own regex that you know works.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2011 21:31:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Automatically-extracting-field-at-search-time/m-p/29523#M5960</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-06-20T21:31:07Z</dc:date>
    </item>
  </channel>
</rss>

