Splunk Search

Splunk Field Extraction

sgarvin55
Splunk Employee
Splunk Employee

Out of the box, Splunk performs field extractions of name/value pairs separated by an "=" sign. We would like to know what special characters disrupt this tagging. For instance, name[subname]=value
name;subname=value
name#subname=value

will not tag appropriately. This does tag appropriately -

name_subname=value

How are other special characters handled?

Tags (2)
0 Karma

lguinn2
Legend

Field names in Splunk must contain only alphabetic characters, numbers and underscore. The name may not begin with a number. In some cases, spaces are allowed, but not in automatic field extraction.

I expect that this is what is causing your problem. There are potentially ways around this:

General field extraction info: http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Addfieldsatsearchtime

More detailed info - probably the most useful page: http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Createandmaintainsearch-timefieldextract...

Tons of details here (look halfway down the page for Field Extractions): http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Propsconf

Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...