Splunk Search

Automatically extracting field at search time

rahiparikh
Explorer

Hi,

Previously I was searching and extracting field at search time by explicitly specifying rex command. Now, I want to do the same thing but I want splunk to understand that I want "that" field extracted when relevant data is searched. How can I do using manager? ( Also, I do wish to keep it general i.e. not based on any source or something similar. )

My previous query was -

* | rex "(?<authentication_type>(?i)(password))"

Now, I want to do something like this -

* authentication_type=password

Thanks,
Rahil

0 Karma

Ayn
Legend
0 Karma

Ayn
Legend

If the IFX creates an invalid extraction you can just specify your own regex that you know works.

0 Karma

rahiparikh
Explorer

Hi,

I already tried that but in IFE it extracts some not required results. 😞

Though.. Thanks!

0 Karma

mw
Splunk Employee
Splunk Employee

Manager -> Fields -> Field Extractions

You can basically paste a rex regex into the new extraction. However, an extraction must target a source, sourcetype, or host. I suppose you could set the source value to "*" though.

Reading up on props.conf will give you some insight into this: http://www.splunk.com/base/Documentation/latest/admin/Propsconf

0 Karma

rahiparikh
Explorer

Hi

Thanks for the reply. I am unable to extract the field the way you specified using Manager.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...