Splunk Dev

IFX question

xvxt006
Contributor

Hi,

When i try to extract a field using IFX, the event in which the highlighted filed is not showing up in the newly opened window. So can't even generate a regex for that value. Any suggestions please? i also heard there is advanced version of IFX (i think standalone App). if anyone has link to that can you please give that?

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Hard to understand what's happening given the details.

However, here is the app that you were referring to:

http://apps.splunk.com/app/494

0 Karma

xvxt006
Contributor

Thank you for the App. My question is..One more time 🙂

say we have the below event and i want to extract ReadyToSubmitToFraud. So i selected that and clicked on "Extract field" from the dropdown on the left which opens IFX in another window and gives sample events. In the sample Events it does not have the event i have the field. So how can i generate the regex

2013-09-05 15:55:02,403 INFO 10.81.193.150 [AbstractOrderSubmitJob] {"order_status_counts":{"Fraud":"69","ReadyToSubmitToFraud":"962",

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...