All Apps and Add-ons

Splunk Field Extraction app

Fatimabegum12
Engager

The source for an app is not displaying in the Splunk, when using The extraction tool -UFX

0 Karma

Fatimabegum12
Engager

App is running on the search head. How do configure that app to look for the logs on the windows forwarders?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Try upgrading to 6.3. There are a lot of enhancements to Splunk core and the IFX!

0 Karma

Fatimabegum12
Engager

App is running on the search head. How do configure that app to look for the logs on the windows forwarders?

0 Karma

Fatimabegum12
Engager

how do we omit one of the search results this is the extraction we are using but it shows one of the unwanted results
PROCESSSTATUS - (?P\D+)

we just want Pro APPROVED but it is also giving us PREP APPROVED 11/15/25 3:00:00 PM ........

0 Karma

hagjos43
Contributor

Can you provide sample logs? I'd be happy to write a regex for you.

0 Karma

Fatimabegum12
Engager

This app is working for linux based forwarders but I condifugred inputs for windows logs and those windows logs are not coming up in splunk

0 Karma

Fatimabegum12
Engager

we can see the linux path in the drop down not the windows paths to the logs

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Where are you running the app? Should be on the search head, not forwarders.

0 Karma

Fatimabegum12
Engager

Please find screenshot of the app

0 Karma

jsven7
Communicator

@Fatimabegum12 is Splunk's built in field extractor tool not working for you? I can walk you through using that field extractor.

0 Karma

Fatimabegum12
Engager

alt text

0 Karma

Fatimabegum12
Engager

Splunk version 6.0.7
Field Extractor App (UFX)

In the pick a source field we are not able to not able to see the new log paths we configured on our windows forwarder.

monitor stanza is only configured on the forwarder only not on the indexer.

0 Karma

Fatimabegum12
Engager

Hi chris,
can you please help here

0 Karma

ChrisG
Splunk Employee
Splunk Employee

I have not actually used the app, so I can't offer any insight. Hopefully the information you have now provided will enable other community members to answer. There is a built-in interactive field extraction feature in Splunk Enterprise 6, see Extract fields interactively with IFX and Use the Field Extractions page in Splunk Web in the Knowledge Manager Manual for information about that.

0 Karma

Fatimabegum12
Engager

Can someone pleas help with this issue?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Please provide additional details so the community can help you. What version of Splunk Enterprise are you using, what is the app you refer to, what steps are you taking, can you provide any sample searches and results...?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...