Splunk Search

Extraction failing on certain events

srinivas_gowda
Path Finder

Hello all,

 

I have been facing problem with the below extraction where the extraction is working on a few events and not on others. Please help on how this can be fixed.

 

Below are the different kind of alerts:

 

The extraction is working as expected on the below alert:

50271234,00004105,00000000,1600,"20210901225500","20210901225500",4,-1,-1,"SYSTEM","","psd217",46769359,"MS932","Server-I ジョブ(Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B:@5V689)を開始します(host: UXC510, JOBID: 56620)","Information","User","/App/App/Server","JOB","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","JOBNET","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX","User:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","START","20210901225500",""

 

The same extraction is not working on the below alerts and is extracting the underlined red fields which is not expected and need to extract the green marked fields.

50271233,00004125,00000000,1600,"20210901225500","20210901225500",4,-1,-1,"SYSTEM","","psd217",46769358,"MS932","KAVS0278-I ジョブ(AJSROOT1:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B:@5V689)のサブミットを開始します","Information","User","/App/App/Server","JOB","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","JOBNET","Server:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX","User:/新基幹_本番処理/値札発行/04_値札指示データ連携_午前1TAX/V9B01_B","START","20210901225500",""


50271226,00004106,00000000,3088,"20210901225446","20210901225446",4,-1,-1,"SYSTEM","","psd240",316413750,"MS932","Server-I ジョブ(Server:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック/EDI送信情報リスト_HULFT送信:@50R6189)が正常終了しました(host: PSC666, code: 0, JOBID: 88039)","Information","User","/App/App/Server","JOB","Server:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック/EDI送信情報リスト_HULFT送信","JOBNET","Server:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック","AJSROOT1:/新基幹_本番処理/MCS/監視/09_注文送信未更新項目チェック/EDI送信情報リスト_HULFT送信","END","20210901225446","20210901225446","0"

 

Please help in resolving this.

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What extraction are you currently using?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...