Follow these steps to add a custom field extraction for a response:
- Log in to your Splunk server.
- In the top right-hand corner, click on the Settings menu and then click on the Fields link.
- Click on the Field extractions link:
- Click on New.
- In the Destination app field, select the search app, and in the Name field, enter response. Set the Apply to dropdown to sourcetype and the named field to access_combined. Set the Type dropdown to Inline, and for the Extraction/Transform field, carefully enter the (?i)^(?:[^"]*"){8}s+(?P<response>.+) regex:
- Click on Save.
- On the Field extractions listing page, find the recently added ...