<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with automatic field detection in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34721#M7524</link>
    <description>&lt;P&gt;Can you post an event that does not cause this problem?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2013 15:47:37 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2013-08-14T15:47:37Z</dc:date>
    <item>
      <title>Issue with automatic field detection</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34720#M7523</link>
      <description>&lt;P&gt;We have customized our internal applications to a custom key=value schema and it usually works well. Splunk usually recognizes the fields just fine. However in one case it fails.&lt;/P&gt;

&lt;P&gt;If the Logline contains&lt;BR /&gt;
JSocketPlugInImpl: handled :/Workflow/getNextActions&lt;/P&gt;

&lt;P&gt;Then the following line&lt;BR /&gt;
Aug 14 14:34:51 172.26.1.10 14.08.2013 16:41:35 level=INFO  stage=prod component=E3 application=evn version=V_06_02_08 service=/Workflow/getNextActions user=xXxXx JSocketPlugInImpl: handled :/Workflow/getNextActions, ReqLen[b]=1000, RspLen[b]=5505 (LogDecorator.java, line 118)&lt;/P&gt;

&lt;P&gt;gives me in the field user "xXxXx JSocketPlugInImpl: handled :/Workflow/getNextActions"&lt;/P&gt;

&lt;P&gt;Is there something i need to tweak? Or do we have to always put values into " ?&lt;/P&gt;

&lt;P&gt;A working logline would be&lt;BR /&gt;
Aug 15 07:08:26 172.26.1.10 15.08.2013 09:09:51 level=INFO  stage=prod component=E3 application=evn version=V_06_02_08 service=/Workflow/setContainer user=xXxXx HPVTraceHandler: Execution of request /Workflow/setContainer [375961] RC=0 took ms: 0 (LogDecorator.java, line 118)&lt;/P&gt;

&lt;P&gt;Seems to only affect lines with "JSocketPlugInImpl:"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:34:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34720#M7523</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2020-09-28T14:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with automatic field detection</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34721#M7524</link>
      <description>&lt;P&gt;Can you post an event that does not cause this problem?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2013 15:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34721#M7524</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-14T15:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with automatic field detection</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34722#M7525</link>
      <description>&lt;P&gt;Splunk will by default recognize field=value pairs and will also by default use "," as a delimiter between field value pairs. So this is simply default behaviour.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2013 19:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34722#M7525</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-08-14T19:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with automatic field detection</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34723#M7526</link>
      <description>&lt;P&gt;I have augmented the description.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2013 07:11:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34723#M7526</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2013-08-15T07:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with automatic field detection</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34724#M7527</link>
      <description>&lt;P&gt;We'll change the app logging to see if it helps but yeah makes sense. Will close the question when we have verified this.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2013 12:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-automatic-field-detection/m-p/34724#M7527</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2013-08-15T12:51:49Z</dc:date>
    </item>
  </channel>
</rss>

