Reporting

Unable to extract fields from raw logs, how can I extract fields in this case?

POR160893
Builder

Hi,

I have a number of raw logs that I need to extract some fields from.

When I go to "Event Actions" and then "Extract Fields", I normally get the following:

POR160893_1-1652280461432.png

However, I am dealing with a number of logs for one index where I get this instead and I cannot extract anything:

POR160893_0-1652280439672.png

How can I extract fields in this case?


Thanks,
Patrick

Labels (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

There are multiple ways to extract fields without using the interactive field extractor.
If you are comfortable with regex, You can try to use the |rex command to start building your extractions in search. After that you can just place them on a props.conf, or add them via settings >> fields >> field extractions.

If you are not comfortable with regex, you can post a sample of your data and we can help you out with that. 😉

------------
Hope I was able to help you. If so, some karma would be appreciated.
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...