Splunk Enterprise

Field extraction failed for Lab 8 of Splunk Fundamentals 2

OlafH
New Member

Dear,

I was following along the Lab 8 exercise of Splunk Fundamentals 2. However the field extraction failed and an unexpected result was observed. Please see the screenshots below

IP has been highlighted as 'src'

OlafH_0-1614340456028.png

One row selects the wrong result

OlafH_1-1614340493501.png

 

Add sample event and highlighting fails the extraction

OlafH_2-1614340534596.png

 

I am still able to continue with the training but this might be something you want to look into. 

Kind regards,

Olaf

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...