Splunk Search

Field extraction doesn't show full log

jared_anderson
Path Finder

I am trying to extract a line "lockouttime=*" it is on line 107. when I use the extract field tool. It only shows the first 10 or so lines. Is there a way to make it show all lines from the logs?

Tags (2)
0 Karma
1 Solution

jared_anderson
Path Finder

(?i)lockouttime=(?P<LockOutTime>.+)

View solution in original post

0 Karma

jared_anderson
Path Finder

(?i)lockouttime=(?P<LockOutTime>.+)

0 Karma

jared_anderson
Path Finder

the lockouttime line could look like this:

lockoutTime=09:38.14 AM, Mon 01/28/2013

if it matters.

0 Karma

jared_anderson
Path Finder

A lot of the log I had to cut out because of character limit.

msExchHideFromAddressLists=TRUE
manager=CN=******\, Dan,OU=Technical Support,OU=Corporate Office,OU=CGS Users,DC=******,DC=local
lastLogonTimestamp=12:20.04 PM, Mon 01/21/2013
dSCorePropagationData=\x3?\xE@?\x4&??V??~[?|$??YoX??y\x1C??O?\x1C| ??A\xF\x1F?\x3hS?4??U20121102172743.0Z|20121017184820.0Z|20121016140931.0Z|20121012204612.0Z|16010714223649.0Z
mSMQDigests=\x3?\xE@?\x4&??V??~[?|$??YoX??y\x1C??O?\x1C| ??A\xF\x1F?\x3hS?4??U
mSMQSignCertificates=\x3
lockoutTime=0
logonHours=<binary>
0 Karma

RicoSuave
Builder

Post a sample event on here and i'm sure either one of us will come up with the proper regex for you. I believe this is a known limitation right now for the extract field tool.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...