Getting Data In

How to extract ingested data and display in interesting fields ?

Kumar2
Loves-to-Learn Lots

Example: MyNameisKumar I want name=kumar from this ingested Data . Please help me with the solution 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Kumar2,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.2.3/Knowledge/WhatisSplunkknowledge Splunk recognize by itself the pairs "field=value".

For the other extraction you can use a Technical Add-On for the standard sources (e.g. Windows, Linux, etc...) or for other sources you have to extract fields by yourself identifying the rule to extract the field and creating a regex.

I could help you if you share some sample of your logs indicating what you want to extract.

regex101.com could help you.

using your sample:

| rex "MyNameis(?<name>\w+)"

that you can test at https://regex101.com/r/PIXYtT/1 

Ciao.

Giuseppe

0 Karma

Kumar2
Loves-to-Learn Lots

No sir

0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...