Splunk Search

How to use the query that Field extractor generate to use in your search

phamxuantung
Communicator

Hi, so I try to use Field Extractor (in Extract new fields) to extract some fields from raw logs to make a table. I have successfully show it on my end but other can't. So I want to apply the query that it auto generate in my own search. The query is:

^[^>\n]*>\s+\w+<(?P<Portname>[^>]+)[^:\n]*:\s+(?P<Status>\w+) at <(?P<IP>[^:]+):(?P<Port>[^>]+)

How do I apply it to Splunk search?

Labels (3)
0 Karma
1 Solution

Vardhan
Contributor

Hi @phamxuantung ,

If the fields are only visible to you but other can't .It means the extractions which you have created are in private.Make it global then others can make use of it.

If you want to put it in search then use the 

Rex command

|rex "^[^>\n]*>\s+\w+<(?P<Portname>[^>]+)[^:\n]*:\s+(?P<Status>\w+) at <(?P<IP>[^:]+):(?P<Port>[^>]+)"

If this answer helps you then upvote it.

View solution in original post

Vardhan
Contributor

Hi @phamxuantung ,

If the fields are only visible to you but other can't .It means the extractions which you have created are in private.Make it global then others can make use of it.

If you want to put it in search then use the 

Rex command

|rex "^[^>\n]*>\s+\w+<(?P<Portname>[^>]+)[^:\n]*:\s+(?P<Status>\w+) at <(?P<IP>[^:]+):(?P<Port>[^>]+)"

If this answer helps you then upvote it.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...