March 2018
Beginner to intermediate
576 pages
13h 29m
English
There are several ways to define a field. Let's start by using the Extract Fields interface. To access this interface, choose Extract Fields from the workflow actions menu next to any event:

This menu launches the Extract Fields view:

In Splunk version 6.2, we have access to a wizard which helps us provide the information required for Splunk to attempt building a regular expression that matches.
Although you may choose multiple fields, in this case, we specify Error:
In the popup, you can provide a custom ...
Read now
Unlock full access