Splunk Search

How is priority handled for manual and automatic field extractions?

pinVie
Path Finder

HI,

how is priority handled in regards to extractions.

Lets assume I have an EXTRACT in props.conf extracting some field and calling it "user". E.g:

EXTRACT-uname = Username:(?<user>.*?)\s

Now in the same event I have a dynamic part e.g., a URL which somewhere/sometimes may contain "user=Peter".
So withing this event I'd have the field "user" twice - once extracted by my extraction, once automatically by Splunk (because it is a field value pair).

Which value will the field user have?

To mitigate this issue I currently switch off auto field extractions, but that's not how I like it to do.

Thx !

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

It will have both contents when you look at the field list (so one of them might already be present in 100% of the fields, but there can be further entries as well), but when you use the field in a command such as table you will get the one from your field extraction.

The field extraction is (usually) defined in the local space of either your user or the app, which is why it will have a higher precedence than the standard defined in the default.

View solution in original post

jeffland
SplunkTrust
SplunkTrust

It will have both contents when you look at the field list (so one of them might already be present in 100% of the fields, but there can be further entries as well), but when you use the field in a command such as table you will get the one from your field extraction.

The field extraction is (usually) defined in the local space of either your user or the app, which is why it will have a higher precedence than the standard defined in the default.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...