Field Extractor: Validate step
The Validate step of the field extractor is for regular-expression-based field extractions only.
Validate your field extraction in the Validate step of the field extractor. The field extractor provides the following validation methods:
- Review the event list table to see which events match or fail to match the field extraction. See "Preview the results of the field extraction".
- Report incorrect extractions to the field extractor by providing counterexamples. In response, the field extractor attempts to improve the accuracy of the regular expression.
- Manually edit the regular expression. See "Manually edit the regular expression".
When you are done validating your field extractions, click Save to save the extraction.
Provide counterexample feedback
This is an optional action for the Validate step.
If you find events that contain incorrectly extracted fields, submit those events as counterexample feedback.
- Find an event with a field value that has been incorrectly extracted.
- The highlighted text is not a correct value for the field that the highlighter represents.
- Click the gray "X" next to the incorrect field value.
- The field extractor displays the counterexample event above the table, marking the incorrect value with red strikethrough. It also updates the regular expression and its preview results.
- If a counterexample does not help, remove it by clicking the blue "X" to the left of the counterexample event.
Field Extractor: Rename Fields step
Field Extractor: Save step
This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4