Splunk Search

Issues with Field Extraction - Extracted Field Not Showing Up in Search Head (in search)

SplunkDash
Motivator

Hello,

I extracted a few numbers of fields through SPLUNK web interface (see below) using REGEX/REX (see below), all fields are extracted as expected and showing no errors in preview. But no/any extracted fields are not showing up from search head (or in my search).  Any thoughts? Your recommendation will be highly appreciated. Thank you so much.

 Extracted through this SPLUNK Web Interface:

SplunkDash_0-1656276009493.png

Sample Data

TESTUser|TESTSYSTEM|DNSTEST|USERTEST|CREATE_SUPER_USER_GROUP|TEST_ELEMENT<GROUP_NAME_group3>|19e4e88e-7fb1-4309-b8a3-93180e41ef86|76.253.69.172|00||2022-04-14T23:59:33.059-0400|{dsUrn: testgroup:'da04c367-b41c-421a-85e1-d5ab759c0c82'}|NA|||||10.207.92.23|23|

TESTUser|TESTSYSTEM|DNSTEST|USER|VIS_EXPORT_EXCEL|TEST_ELEMENT<DNSTES_801482320>|ce01fdc2-2bbe-45ef-845b-f79576e215bf|65.144.148.136|00||2022-05-09T10:21:44.021-0400|{dsUrn: testgroup:'6f10e8f8-100b-4482-9b09-10e18504924c'}|NA|||||10.207.92.23|23|23as

REGEX/REX

^(?P<UserID>\w*)\|(?P<UserType>\w*)\|(?P<System>\w*)\|(?P<EventType>\w*)\|(?P<EventId>[^\|]*)\|(?P<Subject>[^\|]*)\|(?P<SID>[^\|]*)\|(?P<IPAddr>[^\|]*)\|(?P<EventStatus>[^\|]*)\|(?P<Msg>[^\|]*)\|(?P<TimeStamp>[^\|]*)\|(?P<DATA>[^\|]*)\|(?P<Period>[^\|]*)\|(?P<MCode>[^\|]*)\|(?P<Type>[^\|]*)\|(?P<Type2>[^\|]*)\|(?P<DeviceId>[^\|]*)\|(?P<DesIP>[^\|]*)\|(?P<Code>[^\|]*)\|(?P<Headers>.*)

Labels (3)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

You're not making this easy XD

But seriously - with more complicated setups and/or defining the extractions in props/transforms this could be an issue of restarting the server to "catch up" with the new settings but if you edit them via gui, they should work pretty immediately. You could force reload of your apps with https://<your-server>/en-GB/debug/refresh/ just to be sure.

View solution in original post

SplunkDash
Motivator

Hello,

Thank you so much for your response, truly appreciate it. I search it in smart mode.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. And what is your architecture? Because first you say about defining the fields in "Splunk web interface" and then you specifically talk about search-head. Do you have all-in-one installation, indexer cluster and single SH, SH cluster?

SplunkDash
Motivator

Hello,

Yes, all are in one Installation. Thank you!

 

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

And you're sure you don't have permission issues? (like if you defined the extractions using one user, set is as private but search with another user; or defined the extractions in context of a single app and set it to "single app" but search from another app (most typically - the search app))

SplunkDash
Motivator

It's a good point....I define it as global (all apps)

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You're not making this easy XD

But seriously - with more complicated setups and/or defining the extractions in props/transforms this could be an issue of restarting the server to "catch up" with the new settings but if you edit them via gui, they should work pretty immediately. You could force reload of your apps with https://<your-server>/en-GB/debug/refresh/ just to be sure.

PickleRick
SplunkTrust
SplunkTrust

Are you searching in fast or verbose mode?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...