Reporting

Unable to extract fields from raw logs, how can I extract fields in this case?

POR160893
Builder

Hi,

I have a number of raw logs that I need to extract some fields from.

When I go to "Event Actions" and then "Extract Fields", I normally get the following:

POR160893_1-1652280461432.png

However, I am dealing with a number of logs for one index where I get this instead and I cannot extract anything:

POR160893_0-1652280439672.png

How can I extract fields in this case?


Thanks,
Patrick

Labels (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

There are multiple ways to extract fields without using the interactive field extractor.
If you are comfortable with regex, You can try to use the |rex command to start building your extractions in search. After that you can just place them on a props.conf, or add them via settings >> fields >> field extractions.

If you are not comfortable with regex, you can post a sample of your data and we can help you out with that. 😉

------------
Hope I was able to help you. If so, some karma would be appreciated.
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...