I've been trying to extract fields from a log at search time with only the help of props.conf. in the spunk docu I read that EXTRACT would be good in that case, especially cause I try to extract multiple fields at once.
this is my EXTRACT in props.conf so far:
EXTRACT-fields = (?P<src_ip>\d*\.\d*\.\d*\.\d*)(?=\ \d* TCP_)\s(?P<bits>\d*)\s(?P<tcp_state>\w*_\w*)\s
this would go on for a while with different fields but it doesn't work. what do I do wrong?
this is how the log looks like for example:
Thanks a lot for any help!
yeah well I guess I have the solution again... *facepalm*.
I've made an field extraction via splunk gui - settings - fields - field extraction and looked at the output. there it said the name of the extraction was
so using this in my props.conf instead of only -fields made it work.... gosh.
hope this helps anyone who comes across this little problem.
View solution in original post