Splunk Search

What's causing the error message in the extraction of new fields?

atemourt
Engager

Why do I get the following error message when I try to extract new fields?

The events associated with this job have no sourcetype information: 1524125445.48

0 Karma
1 Solution

adonio
Ultra Champion

hello there,

please see this answer:
https://answers.splunk.com/answers/578392/field-extraction-issue-on-events-with-no-sourcetyp.html
in general, you have to assign sourcetype at input time in order to apply search time extraction (and other functions) on your data

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,

please see this answer:
https://answers.splunk.com/answers/578392/field-extraction-issue-on-events-with-no-sourcetyp.html
in general, you have to assign sourcetype at input time in order to apply search time extraction (and other functions) on your data

hope it helps

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...