Splunk Search

Splunk Field Extraction

sgarvin55
Splunk Employee
Splunk Employee

Out of the box, Splunk performs field extractions of name/value pairs separated by an "=" sign. We would like to know what special characters disrupt this tagging. For instance, name[subname]=value
name;subname=value
name#subname=value

will not tag appropriately. This does tag appropriately -

name_subname=value

How are other special characters handled?

Tags (2)
0 Karma

lguinn2
Legend

Field names in Splunk must contain only alphabetic characters, numbers and underscore. The name may not begin with a number. In some cases, spaces are allowed, but not in automatic field extraction.

I expect that this is what is causing your problem. There are potentially ways around this:

General field extraction info: http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Addfieldsatsearchtime

More detailed info - probably the most useful page: http://docs.splunk.com/Documentation/Splunk/4.3.2/Knowledge/Createandmaintainsearch-timefieldextract...

Tons of details here (look halfway down the page for Field Extractions): http://docs.splunk.com/Documentation/Splunk/4.3.2/Admin/Propsconf

Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...