Splunk Search

Windows Event: How to get the complete event show up so it can be extracted?

jcolon68
Explorer

I created a Field Extraction and can see it on the list of Field Extractions. How do I add it to the Fields in a search?

I'm trying to extract a field from Windows Event but for some reason, when trying to extract, the whole message is not coming through. So the part of the message I'm trying to extract doesn't show up.

How can I get the complete message from the Event show up to extract?

0 Karma

Vijeta
Influencer

@jcolon68 Can you be more precise please. If you created a field extraction for a sourcetype (Inline), your search on that sourcetype shall give you the field that you extracted via field extraction.

0 Karma

jcolon68
Explorer

I created the Field Extraction from a search. I apologize , I'm fairly new to splunk not sure what you mean by creating it for a sourcetype (Inline).
I created the Field, re ran the same search ., but I don't see the new field in available fields.

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...