Splunk Search

Field extration based on Event Type

resparis
New Member

Hi I have created a custom Event type and I would like to perform some field extraction based on the new event type, but I can't do it. I can only extract based on the Host, Source and sourcetype

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Yes, host source sourcetype only.

See http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf - specifically, the section explaining .

View solution in original post

0 Karma

ykys97
Explorer

Eventtype produced under the conditions of a particular field >>

AS-IS

index=AAA (keyworld1 OR kewyorld2) AND (keyworld3)

To-BE

index=AAA (Specific_Field="keyworld1" OR Specific_Field="kewyorld2") AND (Specific_Field="keyworld3")

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yes, host source sourcetype only.

See http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf - specifically, the section explaining .

0 Karma

mathewboarman
Explorer

Nine years on...   

is it possible yet to define field extractions for particular eventtypes  ?

Defining them  on a sourcetype basis is too generic... one extraction does not fit all events for a given source type.

Example.  -    Linux file  /var/log/secure   contains Username in different places for successful login and for failed login...   so two extractions are required for the same field  "Username"   Is this a reliable way to do it... ?   Will the extractions conflict or will the results just be merged?

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...