Splunk Dev

IFX question

xvxt006
Contributor

Hi,

When i try to extract a field using IFX, the event in which the highlighted filed is not showing up in the newly opened window. So can't even generate a regex for that value. Any suggestions please? i also heard there is advanced version of IFX (i think standalone App). if anyone has link to that can you please give that?

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Hard to understand what's happening given the details.

However, here is the app that you were referring to:

http://apps.splunk.com/app/494

0 Karma

xvxt006
Contributor

Thank you for the App. My question is..One more time 🙂

say we have the below event and i want to extract ReadyToSubmitToFraud. So i selected that and clicked on "Extract field" from the dropdown on the left which opens IFX in another window and gives sample events. In the sample Events it does not have the event i have the field. So how can i generate the regex

2013-09-05 15:55:02,403 INFO 10.81.193.150 [AbstractOrderSubmitJob] {"order_status_counts":{"Fraud":"69","ReadyToSubmitToFraud":"962",

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...