- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Permanent Field extraction
Trying to get permanent field extraction for a field. Tried to use field extraction tabs in fields given regex there but getting failed. Giving the same in search working. I don't know why.
Below is the event:
host: juniper-uat.systems.fed
Connection: keep-alive sec-ch-ua-platform: ""Windows""
X-Requested-With: XMLHttpRequest
Need to extract the host value as 'fqdn' permanently.
given this regex - Host:\s(?<fqdn>(.+))\n in field extraction as attached below:
But it is extracting whole event value starting from fqdn value. Not extracting correctly.
Please help me in this regard.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Karthikeya
It could be access permission to the extracted field. Go to the menu Settings > Fields, click on Field Extractions, and check if the permission for your field is correct. To ensure access for all users, set the app permissions to global and the Role permissions to Read for Everyone.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Karthikeya ,
I could be more detailed, if you can share the full event, anyway, you have to create a regex like the following:
| rex "host: (?<host>[^\s\n]+)"
Ciao.
Giuseppe
