All Apps and Add-ons

Logs not extracting

usmsplunksme
Explorer

Hi all,
any assistance with this app would be grateful. I managed to connect to our LA workspace and receive logs in splunk, but none of the logs have any extractions.

any assistance would be appreciated.

0 Karma

edhealea
Path Finder

I couldn't find any thing published for this so I had to create a field extraction for each individual query that we implemented. It took a few tries on each one. Just when I thought I had it, MS would through a new format in the query but they have been pretty stable lately. They are not the prettiest regexes but they are working for us.

0 Karma

grout
Explorer

I am facing the same issue with the kusto graber and its not able to parse the json format 

0 Karma

edhealea
Path Finder

Did you ever make any head way with this? I am having the same issue with pulling in log analytics events from Azure using the Grabber.

0 Karma

02sangeet
Engager

Could you please help us, giving some idea about the extraction you used to solve this issue. I am also facing the same issue here, though  we are able to fetch some data from MS Azure log analytics but data shows only header part.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...