Getting Data In

NOT extracting key pair values found in a URL

torowa
Path Finder

Hi Splunkers.

Is there a way to prevent the extraction of KPV in a specific field/fields?

To explain further, a set of firewall logs contains a number of key=value pairs.
These are being extracted automatically by Splunk.

There is also (depending on the site) what appears to be key-values within the URL field.
These aren't values I am interested in extracting as they are simply part of the page served from the remote web server.

Is there any way to NOT extract these (perceived) key-values on a per field basis (for URL and other fields) as once extracted, some end up with field names matching CIM field names.

The only setting relating to this seems to be for disabling key-values extraction for an entire sourcetype, not individual fields.

Thanks.

0 Karma

FrankVl
Ultra Champion

I think you would indeed need to disable auto KV (so set KV_MODE=none) and define a suitable field extraction explicitly for that sourcetype.

Since you're mentioning firewall logs, isn't there a TA available that takes care of such things for you? I would expect that most firewall brands have a TA on splunkbase?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...