List of questions
Related questions
Question 249 - SPLK-1002 discussion
Using the Field Extractor (FX) tool, a value is highlighted to extract and give a name to a new field. Splunk has not successfully extracted that value from all appropriate events. What steps can be taken so Splunk successfully extracts the value from all appropriate events? (select all that apply)
A.
Select an additional sample event with the Field Extractor (FX) and highlight the missing value in the event.
B.
Re-ingest the data and attempt to extract from a new dataset.
C.
Click on the event where the field was not extracted and choose ''Change to Delimited'.
D.
Edit the regular expression manually.
Your answer:
0 comments
Sorted by
Leave a comment first