I have Event Output below
RPT: /DailyTestReport
I want to create a field as RPT and Field value as "/DailyOperation Reports ".
You could use rex on _raw field like so:
<your sourcetype> | rex field=_raw "RPT: (?<RPT>\w+)"
A better way would be to get your field extractions specified in props.conf and transforms.conf. Have a look at the documentation at the following link:
http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/Aboutfields
Hi there are many ways :
lets do IFX.
1-from the result of your search.click the arrow to the left of timestamp of an event.
2-select EXTRACT FIELD under EVENT ACTION
3-the IFX opens in a new window, EXTRACT FIELDS.
4-Now it depending on the splunk version,the UI will be different. but in 6.2... there are steps.
5- at the first or the 2nd step, where you have a sample event, SELECT THE STRING you consider as value, a text box will be open and PUT THE NAME OF THE FIELD.
6-after that follow carefully the other steps ......
for other ways see:
docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/Managesearch-timefieldextractions
Use a field transformation to extract both the filename and the value.
See both:
http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Transformsconf
and
http://answers.splunk.com/answers/214487/can-i-extract-a-field-with-a-regexed-dynamic-field.html
You can access this via Splunkweb under settings -> fields -> field transformations, as well. Otherwise, you could do dances around with rex as well.