Hello,
I extracted a few numbers of fields through SPLUNK web interface (see below) using REGEX/REX (see below), all fields are extracted as expected and showing no errors in preview. But no/any extracted fields are not showing up from search head (or in my search). Any thoughts? Your recommendation will be highly appreciated. Thank you so much.
Extracted through this SPLUNK Web Interface:
Sample Data
TESTUser|TESTSYSTEM|DNSTEST|USERTEST|CREATE_SUPER_USER_GROUP|TEST_ELEMENT<GROUP_NAME_group3>|19e4e88e-7fb1-4309-b8a3-93180e41ef86|76.253.69.172|00||2022-04-14T23:59:33.059-0400|{dsUrn: testgroup:'da04c367-b41c-421a-85e1-d5ab759c0c82'}|NA|||||10.207.92.23|23|
TESTUser|TESTSYSTEM|DNSTEST|USER|VIS_EXPORT_EXCEL|TEST_ELEMENT<DNSTES_801482320>|ce01fdc2-2bbe-45ef-845b-f79576e215bf|65.144.148.136|00||2022-05-09T10:21:44.021-0400|{dsUrn: testgroup:'6f10e8f8-100b-4482-9b09-10e18504924c'}|NA|||||10.207.92.23|23|23as
REGEX/REX
^(?P<UserID>\w*)\|(?P<UserType>\w*)\|(?P<System>\w*)\|(?P<EventType>\w*)\|(?P<EventId>[^\|]*)\|(?P<Subject>[^\|]*)\|(?P<SID>[^\|]*)\|(?P<IPAddr>[^\|]*)\|(?P<EventStatus>[^\|]*)\|(?P<Msg>[^\|]*)\|(?P<TimeStamp>[^\|]*)\|(?P<DATA>[^\|]*)\|(?P<Period>[^\|]*)\|(?P<MCode>[^\|]*)\|(?P<Type>[^\|]*)\|(?P<Type2>[^\|]*)\|(?P<DeviceId>[^\|]*)\|(?P<DesIP>[^\|]*)\|(?P<Code>[^\|]*)\|(?P<Headers>.*)
You're not making this easy XD
But seriously - with more complicated setups and/or defining the extractions in props/transforms this could be an issue of restarting the server to "catch up" with the new settings but if you edit them via gui, they should work pretty immediately. You could force reload of your apps with https://<your-server>/en-GB/debug/refresh/ just to be sure.
Hello,
Thank you so much for your response, truly appreciate it. I search it in smart mode.
OK. And what is your architecture? Because first you say about defining the fields in "Splunk web interface" and then you specifically talk about search-head. Do you have all-in-one installation, indexer cluster and single SH, SH cluster?
Hello,
Yes, all are in one Installation. Thank you!
And you're sure you don't have permission issues? (like if you defined the extractions using one user, set is as private but search with another user; or defined the extractions in context of a single app and set it to "single app" but search from another app (most typically - the search app))
It's a good point....I define it as global (all apps)
You're not making this easy XD
But seriously - with more complicated setups and/or defining the extractions in props/transforms this could be an issue of restarting the server to "catch up" with the new settings but if you edit them via gui, they should work pretty immediately. You could force reload of your apps with https://<your-server>/en-GB/debug/refresh/ just to be sure.
Are you searching in fast or verbose mode?