Splunk Search

No URL field in the Search base

vistasyslog
New Member

I have three Firewalls splunking, and I cannot see a src_ip or the URL fields in the search base.
Is there a way to get them.
I just started with Splunk so may be Don't have a lot of things required setup right now.
Any help or tips on starting Splunking that may be helpful in the future would be great.

Thanks all
Ansh

Tags (1)
0 Karma

cyue_splunk
Splunk Employee
Splunk Employee

Click he small triangle symbol at the beginning of any event and use the Interactive Field Extract page to extract/define your src_ip or URL fields.

0 Karma

vistasyslog
New Member

Great. Thanks for your help.

0 Karma

cyue_splunk
Splunk Employee
Splunk Employee
0 Karma

vistasyslog
New Member

Thanks for the answer, but I still cannot find the fields.
Is there a syntax that I need to put in ?
Can you give me an example of it ?

Thanks

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...