Getting Data In

Where can I find a good video on field extraction (parsing) ?

Hemnaath
Motivator

Hi All, Can any one share me a good video link explaining about Field Extraction concept on both Index time /Search time field extraction via props.conf. I had gone through the splunk documentation on field extraction method in props.conf but could not able to understand it properly and I am facing lots of problem in this area "parsing". So it will be great if any one can share a video link explaining about field Extraction and parsing.

0 Karma

dkolekar_splunk
Splunk Employee
Splunk Employee

Video Links:
1. https://www.youtube.com/watch?v=Yf5gTNiotnM
2. https://www.youtube.com/watch?v=jQ5RJRe4izM

[Links are for an older version of splunk. But refer it for clearing your concepts. ]

ddrillic
Ultra Champion

My favorite place is youtube. I just searched for field extraction in splunk and several short videos came up..

0 Karma

Hemnaath
Motivator

Hi ddrillic, thanks for your effort on this, It will be great if you can share some videos related to parsing, as I use to get most of the issues related to parsing in my organization.

thanks in advance.

0 Karma

ddrillic
Ultra Champion

Just run this simple search in youtube....

0 Karma

niketn
Legend

@Hemnaath, have you already checked out the following step by step documentation for Interactive Field Extraction?

Also you should try to go through Splunk Search Fundamentals 2 Course on Splunk Education. However, the same is a paid Web Based Instructor Led Training.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Hemnaath
Motivator

Hi Niketnilay, thanks for your effort on this, hey in my environment, we use to get lots of issue related to parsing and i use to go through the props.conf documentation for any parsing related issues, but I am finding it very difficult in resolving the issues tough i am reading the documents very patiently but still unable to get into it. So it will be good if i get any video on the same, any how I will go though the Interactive Field Extraction documentation again.

Meanwhile if you can share me link on the same it will be great.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...