...o match to a field name.
But my "fieldname" is only alpha characters and yet it still does not work.
I did not see anything listed on the Known Issues page for 6.0.2 regarding fieldextractions...
I want to create report for events whose field names haven't been extracted. I have SSH logs of the format "Accepted publickey for user XYZ" , "Accepted publickey for user ABC" and so on. I want t...
...atching unintended fields. Please help how to go with this Jul 15 14:01:32 jiufc1fe330 xinetd[82352]: START: nrpe pid=151239 from=::ffff:14.956.44.41 Jul 15 12:30:36 dyue29200 systemd: Removed slice Use...
...5 01:09:00 6.033 POST /myaccount/json/acc_nitro_login_json.jsp - 302 0]"
I want to get "product" & "myaccount" into a field called page, basically whatever that first word is a...
...ike to separate some of this data during ingestion. I've read through the transforms.conf and props.conf manual pages, but the language on transforming data into a multi-value field isn't very clear to m...
It seems that there is no way to extractfields with a '.' in the name.
I'm trying to usefieldextractors on our older data to create fields matching the newer data json fields.
{ "p...
Has anyone had any success writing fieldextractions for O365 based events collected via the API?
The messages that are generated are HUGE and have multiple fields that contain multiple values....
...lto commit description. I am using the following regex string and it shows to match fine in the regex query fieldextraction page. (?<=Description:\s)(?P<pansys_commitdes&g...
Hi all,
I need to extractthe last appended letter part in the URI field and use eval to term them as:
d = Detail
m = Hover
e = Edit
o = Home Page
My data below consists of this f...
...add theextracted fields in the SearchManager's search query on my page, I get No result found.
How can I resolve this issue and continue to use SplunkJS in my webapp?