Splunk Search

Automatic field extractions best practices on Splunk Cloud

ohookins
New Member

We have a number of different log types, but many of which contain similar fields. I understand the it is preferred to do extraction at search time rather than index time, and automatic field extraction either with regex or delimiters is one such option.

My goal is to extract some of these common fields so that when we are diagnosing an issue under time pressure, we have all of the commonly used fields already extracted and ready for simple search queries, rather than having to do on-the-spot regular expression searches. So far it looks like we have already quite a number of extractions enabled, although I'm not positive how or whether any of them are working.

My questions are:

  1. Are all of these extractions active and used during search time, for any that are saved as Global or App-wide sharing mode? I need to know that the extractions I define will be automatically used by everyone without needing further configuration.

  2. How can I find records that are not being correctly extracted? E.g. fieldname="" doesn't seem to work. I want to search for all records that don't have a particular field defined (because extraction failed or wasn't defined).

  3. What is the behaviour when different extractions overlap in their field names? There may be several that define the name "space" on the same record type for example.

Thanks!

0 Karma

woodcock
Esteemed Legend

Any time that you need to create ANYTHING, first create a new app to own/contain it. We almost always create a Global_KOs app, mostly for CIM and for tags that everybody will need and everything that goes in it will be Global; everything else should be App and contained in the appropriate app. If your guys need some dashboards built on the email, then create an app for it, create the field extractions that you need, build the dashboards that you need and so on.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...