I can successfully parse data with a search query, but putting the same query into a field extraction rule often doesn't show the parsed fields. Here's an example: _sourceCategory=networking/clearpass 184.108.40.206 | parse "Endpoint.Username=*#" as wifi_Username | parse "Endpoint.MAC-Address=*#" as wifi_MACaddress | parse "Endpoint.IP-Address=*#" as wifi_IPaddress When I put this into a search I can see the 3 new entries in the Display Fields list, populated with data. However, I added this exact info into a field extraction and when I just search for the IP address (or the sourceCategory and IP address) the fields don't display. Here's a screenshot of my field extraction rule. Any assistance would be appreciated.
Please sign in to leave a comment.