Splunk Search
Highlighted

Why is my index time extraction not working

New Member

On my Intermediates or Heavy Forwarders and Search Heads I have:
props.conf
[roleextract]
TRANSFORMS-roleextract = extract
role

transforms.conf
[extractrole]
REGEX=\D{3}\D\d{1,4}(...)\d{1,5}
FORMAT = role::$1
SOURCE
KEY = host
WRITE_META = true

fields.conf
[role]
INDEXED = true

I dont get the extracted values thought when I search for this field.
Im probably doing something incorrectly.
Thanks for the help

0 Karma
Highlighted

Re: Why is my index time extraction not working

Motivator

Hi there, can you provide sample data to see if regex match is working.

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.