Output should have only have only field FIELD2 & FIELD3 data.
REPORT-fields = getLogData
DELIMS = "|"
I am sure somewhere i am making mistake.
Do you want them indexed, or extracted at search time?
I want to them to be indexed.
Here's some things that I'd try, one at a time -
A) change to INDEXED_EXTRACTIONS=psv.
(This may not help but should not hurt.)
B) change namespace from REPORT-fields to REPORT-search or REPORT-yourappname.
(This is my best guess of the real issue.)
C) remove pulldown_type clause
(In the admin manual, it says # NOT YOURS. DO NOT SET.)
D) remove disabled clause
(I don't find it in the admin manual for that stanza.)
Tried with the above changes but now I am not getting any data indexed.
which change caused the data to stop indexing?
After restarting splunk all data are getting indexed rather than the two fields.
You can use field transformations in props, TRANSFORMS-q=nq
then in transforms.conf
REGEX=CHINA.* | NEPAL.*
hope this helps..