Splunk Search

Why Sample Events returned from Interactive Field Extractor do not match my original events?

mark_chuman
Path Finder

Hopefully I can explain this one effectively.

I have a search that brings back 3 records. I then select the drop-down field in the leftmost column with an "i" over it. This expands the record and there are more options. There is an "Event Actions" drop-down. I select this and choose "Extract Fields". A new browser tab is opened and I should be able to type in a value in the "Example values for a field" window and click generate and the pattern should be identified in the records. The problem I have is that the Sample Events that are returned are nothing like the 3 records that I was presented with initially. Any insight into what may be happening is welcome.

Thanks!

Tags (2)
0 Karma

mark_chuman
Path Finder

I think I got it. The samples that are returned aren't the exact same, but are the same format so the regex should work fine. Thanks!

0 Karma

mark_chuman
Path Finder

Not sure at which step you are referring to. At what step in the attached document are you talking about? Thanks for the time on this one.

Thanks

Well, I don't have enough karma to upload (Thought we would get those with a Splunk license 🙂 Not sure how I can show you... I have to admit the karma thing is a bit cumbersome (to Splunk moderator).

0 Karma

somesoni2
Revered Legend

This list is based on the event you selected from your search and the field restriction (restriction specified before first pipe'|') you specified.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...