Reporting

Unable to extract fields from raw logs, how can I extract fields in this case?

POR160893
Builder

Hi,

I have a number of raw logs that I need to extract some fields from.

When I go to "Event Actions" and then "Extract Fields", I normally get the following:

POR160893_1-1652280461432.png

However, I am dealing with a number of logs for one index where I get this instead and I cannot extract anything:

POR160893_0-1652280439672.png

How can I extract fields in this case?


Thanks,
Patrick

Labels (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

There are multiple ways to extract fields without using the interactive field extractor.
If you are comfortable with regex, You can try to use the |rex command to start building your extractions in search. After that you can just place them on a props.conf, or add them via settings >> fields >> field extractions.

If you are not comfortable with regex, you can post a sample of your data and we can help you out with that. 😉

------------
Hope I was able to help you. If so, some karma would be appreciated.
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...