Splunk Search

Header Field Extraction Not Working

adityapavan18
Contributor

I have data in los as specified in below sample.

FILEHEADER|^2013-12-18 15:22:07|^v4|^RECORDS

@FIELDS|^FIELD1|^FIELD2|^FIELD3|^FIELD4|^FIELD5

VALUE1.1|^VALUE1.2|^VALUE1.3|^VALUE1.4|^VALUE1.5

VALUE2.1|^VALUE2.2|^VALUE2.3|^VALUE2.4|^VALUE2.5

VALUE3.1|^VALUE3.2|^VALUE3.3|^VALUE3.4|^VALUE3.5

VALUE4.1|^VALUE4.2|^VALUE4.3|^VALUE4.4|^VALUE4.5

As mentioned in http://docs.splunk.com/Documentation/Splunk/6.0/Data/Extractfieldsfromfileheadersatindextime

I tried to extarat field values directly from header.

I used the below configuration in props.conf:

CHECK_FOR_HEADER = true
FIELD_DELIMITER = \|\^
INDEXED_EXTRACTIONS = PSV
PREAMBLE_REGEX = FILEHEADER.*
FIELD_HEADER_REGEX = @FIELDS\|\^
SHOULD_LINEMERGE = false

But doesn't seem to work, can anyone help please??

Tags (2)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Field header regex requires a capture group for the text that contains the fields like below:

 FIELD_HEADER_REGEX = @FIELDS(.*)
0 Karma

MuS
Legend

Hi adityapavan18,

your FIELD_HEADER_REGEX looks not okay, it should be like this:

 @FIELDS\|

the expression is pur regex in FIELD_HEADER_REGEX option, so your ^ was handled as regex command which means Matches the beginning of the string

cheers, MuS

MuS
Legend

oh was that there before? 🙂 well, yes it should. You could test it if you just use @FIELDS and double check the sourcetype that it matches.

0 Karma

adityapavan18
Contributor

MuS, i escaped the caret rite..so it will take it a literal ^ and not start of line rite??

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...