Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is it possible to put a conditional statement in a field extraction?

$
0
0
I have files I am ingesting that have variable formats. I want to pick those lines out that only have an IP address as the third value and extract that as **srcIP**. Is this possible to essentially put a conditional statement in so I don't get all the garbage from the "other" data in the logs?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>