Splunk Search

Automatically extracting field at search time

rahiparikh
Explorer

Hi,

Previously I was searching and extracting field at search time by explicitly specifying rex command. Now, I want to do the same thing but I want splunk to understand that I want "that" field extracted when relevant data is searched. How can I do using manager? ( Also, I do wish to keep it general i.e. not based on any source or something similar. )

My previous query was -

* | rex "(?<authentication_type>(?i)(password))"

Now, I want to do something like this -

* authentication_type=password

Thanks,
Rahil

0 Karma

Ayn
Legend
0 Karma

Ayn
Legend

If the IFX creates an invalid extraction you can just specify your own regex that you know works.

0 Karma

rahiparikh
Explorer

Hi,

I already tried that but in IFE it extracts some not required results. 😞

Though.. Thanks!

0 Karma

mw
Splunk Employee
Splunk Employee

Manager -> Fields -> Field Extractions

You can basically paste a rex regex into the new extraction. However, an extraction must target a source, sourcetype, or host. I suppose you could set the source value to "*" though.

Reading up on props.conf will give you some insight into this: http://www.splunk.com/base/Documentation/latest/admin/Propsconf

0 Karma

rahiparikh
Explorer

Hi

Thanks for the reply. I am unable to extract the field the way you specified using Manager.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...