Splunk Search

Why has field extractor incorrectly mapped the fields or shows same value for multiple fields?

sh254087
Communicator

I have a long event which I tried to extract fields from, using splunk's extract additional fields feature. 

I chose comma delimited extraction and named the fields appropriately. I have 117 fields altogether and when I to display the fields with the table command, I noticed that there are a couple of data-to-field mismatches. 

 

field3 value is replicated for field5. 

field4 value is replicated for field8.

Please refer the screenshot for better understanding:regex errorregex error

I have checked the transforms.conf and that looks fine.

I'm not sure how to get over this issue.

Any help in guiding towards the right solution will be highly appreciated. 

Labels (5)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...