Splunk Enterprise

Field Extractions

itsmevic
Communicator

Hello I have a basic search that I am running from the following:

index=sso

This search returns a lot of events.  Within those log events, I would like to extract two pieces of  information and create fields for them both, they are:

"saml:Issuer" AND "saml:Audience>https://"

I'd then like to run a simple query against these two new fields

index=sso sourcetype="pingfed*"

table saml:Issuer saml:Audience>https://

What would be the most efficient way of doing this field extraction step-by-step?

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Please share some sample events.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...