<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can an already indexed field be hid globally since it can't be removed? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446707#M149829</link>
    <description>&lt;P&gt;for GDPR compliance I need to modify a ClientIP field that is already indexed (4+ year so far) and wipe it.&lt;BR /&gt;Was thinking on dumping the whole index and load it to a different one, but that will blow my license with just a couple of days of data.&lt;/P&gt;
&lt;P&gt;As it seems is not possible to delete it from index, there is any chance of hiding it from all queries or change its value globally?&lt;/P&gt;
&lt;P&gt;thanks.&lt;/P&gt;</description>
    <pubDate>Sat, 21 Nov 2020 06:19:47 GMT</pubDate>
    <dc:creator>matiasruiz</dc:creator>
    <dc:date>2020-11-21T06:19:47Z</dc:date>
    <item>
      <title>Can an already indexed field be hid globally since it can't be removed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446707#M149829</link>
      <description>&lt;P&gt;for GDPR compliance I need to modify a ClientIP field that is already indexed (4+ year so far) and wipe it.&lt;BR /&gt;Was thinking on dumping the whole index and load it to a different one, but that will blow my license with just a couple of days of data.&lt;/P&gt;
&lt;P&gt;As it seems is not possible to delete it from index, there is any chance of hiding it from all queries or change its value globally?&lt;/P&gt;
&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Nov 2020 06:19:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446707#M149829</guid>
      <dc:creator>matiasruiz</dc:creator>
      <dc:date>2020-11-21T06:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: As an already indexed field can't be removed, can I hide it globally?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446708#M149830</link>
      <description>&lt;P&gt;You want to hide all data which has the ClientIP field from searching OR just mask that field value?&lt;/P&gt;

&lt;P&gt;Also, you could do a summary indexing to move data from one index to another index, without utilizing the license.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 21:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446708#M149830</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-05T21:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: As an already indexed field can't be removed, can I hide it globally?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446709#M149831</link>
      <description>&lt;P&gt;I want to just mask that field value.&lt;/P&gt;

&lt;P&gt;And where can I read more about that summary indexing?, sounds like I could transform the data on the fly?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 21:47:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/446709#M149831</guid>
      <dc:creator>matiasruiz</dc:creator>
      <dc:date>2018-06-05T21:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: As an already indexed field can't be removed, can I hide it globally?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/530255#M149832</link>
      <description>&lt;P&gt;I would also appreciate more information on using summary indexes to store "transformed" data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation on summary indexes all describe using it to store summary information. Is there any difference?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 17:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/530255#M149832</guid>
      <dc:creator>richardAtOmni</dc:creator>
      <dc:date>2020-11-20T17:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: As an already indexed field can't be removed, can I hide it globally?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/530278#M149833</link>
      <description>Hi&lt;BR /&gt;Collect is the command how you could create summary indexes. &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Collect" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Collect&lt;/A&gt;&lt;BR /&gt;It has some restrictions e.g.with sourcetypes.&lt;BR /&gt;Basically you could mask _raw and fields on your queries, BUT there is a way(s) to get the original data on screen if you know what you are doing. So only way to really mask it is reindexing it.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 20 Nov 2020 22:45:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-an-already-indexed-field-be-hid-globally-since-it-can-t-be/m-p/530278#M149833</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-20T22:45:57Z</dc:date>
    </item>
  </channel>
</rss>

