Getting Data In

Bro Logs: How can I remove fields that an analyst accidentally created, and how do I fix a parsing error?

nb1030
New Member

I have an analyst that was playing around trying to extract a new field. Unfortunately, he used the delimiter function and instead of backing out of it, he saved it. So on top of the normal fields being parsed out, I have over 60 fields called field1, field2, field3, etc. How can I go about removing these? Also, a second part to this question, I have bro_http logs coming in and the contain a "version" field. This field is not being parsed out, instead, everything being parsed out has shifted to the left by one field (i.e. instead of version being 1.1, the version is showing the user_agent information, which should be in the user_agent field one field to the right)? What file can I update to ensure it is parsing out the version?

0 Karma

hardikJsheth
Motivator

The user has done search time extraction and you need too remove it. You can delete unwanted configuration from props.conf files and transforms.conf file . It will be inside the local folder of the app where user was performing extraction.

0 Karma

nb1030
New Member

I was able to find the correct transforms.conf file and fixed my parsing issue. I am still having a difficult time finding the props.conf file to remove the search time extraction. He did it from the search&reporting app. When I look under the search app, the props.conf file only shows EXTRACT-fields = (?i)^(?:[^ ] ){2}(?:[+-]\d+ )?(?P[^ ])\s+(?P[^ ]+) - (?P.+)....Is this what I should be removing? If so, when I commented out the line, it did not get rid of the fields.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...