<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Field Extractor in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759789#M24073</link>
    <description>&lt;P&gt;One addition.&lt;/P&gt;&lt;P&gt;As it has already said this is just for one sourcetype. Then depending on what you have defined for it's permissions, it could be available only for you, only inside one application for all user inside it's context or globally for all applications and all users (unless some application has same named extractions).&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2026 17:32:22 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2026-03-30T17:32:22Z</dc:date>
    <item>
      <title>Splunk Field Extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759773#M24067</link>
      <description>&lt;P&gt;I am new to Splunk Enterprise and I have a question.&lt;BR /&gt;when add new field extraction using Splunk Field Extractor, does the parser it self will be modified and the new field will be applied to all logs by default?&lt;BR /&gt;also do I have to submit any changes to do so or edit any configuration file?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 09:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759773#M24067</guid>
      <dc:creator>osama_11</dc:creator>
      <dc:date>2026-03-30T09:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Field Extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759774#M24068</link>
      <description>&lt;P&gt;The Field Extractor creates relevant configuration entries on the component you're running it on (or across the whole cluster if you're using search head clustering).&lt;/P&gt;&lt;P&gt;The fields will not be applied to _all logs_, just to the specific sourcetype you ran your extractor on.&lt;/P&gt;&lt;P&gt;Anyway, Field Extractor is nice for presentations and showing how schema-on-read works but for production use it's usually better to handle extractions manually in config files.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 12:55:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759774#M24068</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-03-30T12:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Field Extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759789#M24073</link>
      <description>&lt;P&gt;One addition.&lt;/P&gt;&lt;P&gt;As it has already said this is just for one sourcetype. Then depending on what you have defined for it's permissions, it could be available only for you, only inside one application for all user inside it's context or globally for all applications and all users (unless some application has same named extractions).&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 17:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759789#M24073</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-03-30T17:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Field Extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759793#M24074</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316434"&gt;@osama_11&lt;/a&gt;&amp;nbsp;The field extraction will only apply to events of the defined sourcetype, not globally.&lt;/P&gt;&lt;P&gt;Could you please clarify whether you are planning to use these field extractions just for testing, or to roll them out in production?&lt;/P&gt;&lt;P&gt;That will help to determine whether the Field Extractor is sufficient or if you should move to manual configuration management. For production roll out, it is best to manage it via props &amp;amp; transforms configuration files in Splunk.&lt;/P&gt;&lt;P&gt;Refer Field extraction configuration in the documentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/configuration-file-reference/9.2.8-configuration-file-reference/props.conf" target="_blank" rel="noopener"&gt;props.conf | Platform (last updated 2025-07-30T21:23:14.766Z)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.12/Admin/Transformsconf" target="_blank" rel="noopener"&gt;transforms.conf - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this post addressed your question, you can:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Give it&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;karma&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to show appreciation&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Mark it as the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;solution&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if it solved your issue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Add a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;comment&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if you’d like more details&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pencil:"&gt;✏️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 18:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Field-Extractor/m-p/759793#M24074</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-03-30T18:00:46Z</dc:date>
    </item>
  </channel>
</rss>

