Splunk Search

Extraction failing on certain events

srinivas_gowda
Path Finder

Hello all,

 

I have been facing problem with the below extraction where the extraction is working on a few events and not on others. Please help on how this can be fixed.

 

Below are the different kind of alerts:

 

The extraction is working as expected on the below alert:

50271234,00004105,00000000,1600,"20210901225500","20210901225500",4,-1,-1,"SYSTEM","","psd217",46769359,"MS932","Server-I ジョブ(Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B:@5V689)を開始します(host: UXC510, JOBID: 56620)","Information","User","/App/App/Server","JOB","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","JOBNET","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX","User:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","START","20210901225500",""

 

The same extraction is not working on the below alerts and is extracting the underlined red fields which is not expected and need to extract the green marked fields.

50271233,00004125,00000000,1600,"20210901225500","20210901225500",4,-1,-1,"SYSTEM","","psd217",46769358,"MS932","KAVS0278-I ジョブ(AJSROOT1:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B:@5V689)のサブミットを開始します","Information","User","/App/App/Server","JOB","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","JOBNET","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX","User:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","START","20210901225500",""


50271226,00004106,00000000,3088,"20210901225446","20210901225446",4,-1,-1,"SYSTEM","","psd240",316413750,"MS932","Server-I ジョブ(Server:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック/EDI送信情報リスト_HULFT送信:@50R6189)が正常終了しました(host: PSC666, code: 0, JOBID: 88039)","Information","User","/App/App/Server","JOB","Server:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック/EDI送信情報リスト_HULFT送信","JOBNET","Server:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック","AJSROOT1:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック/EDI送信情報リスト_HULFT送信","END","20210901225446","20210901225446","0"

 

Please help in resolving this.

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What extraction are you currently using?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...