Splunk Dev

IFX question

xvxt006
Contributor

Hi,

When i try to extract a field using IFX, the event in which the highlighted filed is not showing up in the newly opened window. So can't even generate a regex for that value. Any suggestions please? i also heard there is advanced version of IFX (i think standalone App). if anyone has link to that can you please give that?

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Hard to understand what's happening given the details.

However, here is the app that you were referring to:

http://apps.splunk.com/app/494

0 Karma

xvxt006
Contributor

Thank you for the App. My question is..One more time 🙂

say we have the below event and i want to extract ReadyToSubmitToFraud. So i selected that and clicked on "Extract field" from the dropdown on the left which opens IFX in another window and gives sample events. In the sample Events it does not have the event i have the field. So how can i generate the regex

2013-09-05 15:55:02,403 INFO 10.81.193.150 [AbstractOrderSubmitJob] {"order_status_counts":{"Fraud":"69","ReadyToSubmitToFraud":"962",

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...