Hi,
I have events that have more than 20 lines of data. In the Field extraction menu only the first 20 lines are shown. This prohibits me from extracting fields that are beyond the 20th line. Is there a way to show more lines? Can I get the required fileds in another way? My fields all have the same format like: $_NAME: VALUE. There are about 1200 different values in one event. Can I auto extract all fields from my events? (they all have the same sourcetype)
Hi
IMHO it's much better to use e.g. https://regex101.com to other similar to define field extractions. Then just add those via conf files or gui. Splunk's own Field extraction menu don't do really good regex patterns if/when you have any complicated pattern to apply.
r. Ismo