My field extractions are not coming up on splunk.
- i added the extractions in props.conf (tested them b4 adding).
- made a metadata folder and added a file local.meta and added the following lines :-
export = system
access = read : [ * ], write : [ admin ]
Any idea, what am i missing ?
I'm sure you know this, but make sure you're not searching in Fast mode.. Second, I would first try doing search time extractions to verify it's capturing 100% of your fields. Then when your confident in your regex, put it in