All Apps and Add-ons

Field Extractor App V 1.6 with Splunk 6.0

nehadoshi89
New Member

We downloaded and installed the Field Extractor App Version 1.6 with Splunk Enterprise 6.0. We have two issues with using the app.

Issue 1: We used the app to extract 10 fields from a single log file. When the system was rebooted only 5 extractions are retained. We are on Splunk Enterprise version 6.0. Some of the rules that are defined in the app were saved while some rules were not saved after reboot. When the extraction is saved as a rule, they are reflected in the props.conf. Once the system is rebooted or when the data is re-indexed, the extractions are no longer listed when the search is initiated.

Issue 2: If we select one particular field e.g. SUCCESS for extraction, it highlights the SUCEESS field but in addition it also highlights some additional non-related data. The issue here is that when we click the “X” button it does not deselect the non-related data. Thus the appropriate field cannot be extracted correctly.

Thanks again. We love this App!

0 Karma
1 Solution

carasso
Splunk Employee
Splunk Employee

1) If the settings are saved in props.conf, they are preserved after reboot.
If must be the case that the regexes are not matching your data. Also, make sure that you actually save each rule created, if there are multiple rules created.

2) Sometimes the app is not able to create a rule that extracts a value you want and not one you don't want. In that case, you'll have to edit the rule (by clicking on 'edit' in the ui)

View solution in original post

0 Karma

carasso
Splunk Employee
Splunk Employee

1) If the settings are saved in props.conf, they are preserved after reboot.
If must be the case that the regexes are not matching your data. Also, make sure that you actually save each rule created, if there are multiple rules created.

2) Sometimes the app is not able to create a rule that extracts a value you want and not one you don't want. In that case, you'll have to edit the rule (by clicking on 'edit' in the ui)

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...