<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I missed a field in my custom sourcetype in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232073#M176565</link>
    <description>&lt;P&gt;And maybe add a sample set of events to the post.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Oct 2016 19:00:39 GMT</pubDate>
    <dc:creator>dmaislin_splunk</dc:creator>
    <dc:date>2016-10-05T19:00:39Z</dc:date>
    <item>
      <title>I missed a field in my custom sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232071#M176563</link>
      <description>&lt;P&gt;I am trying to add a field that I missed on my custom sourcetype.  If I add it to the transforms.conf, the data (event) stops getting indexed. My transforms is a simple delimited fields entry.   Is there a way to add this field to the event after the missing it? Also, will&lt;BR /&gt;
the indexer enter a second event that has the same host, source, sourcetype and event time (_time) ? ...a duplicate event ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 18:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232071#M176563</guid>
      <dc:creator>riotto</dc:creator>
      <dc:date>2016-10-05T18:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: I missed a field in my custom sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232072#M176564</link>
      <description>&lt;P&gt;Need more detail.  What does your inputs.conf, props.conf, and transforms.conf look like?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 18:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232072#M176564</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2016-10-05T18:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: I missed a field in my custom sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232073#M176565</link>
      <description>&lt;P&gt;And maybe add a sample set of events to the post.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 19:00:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232073#M176565</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2016-10-05T19:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: I missed a field in my custom sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232074#M176566</link>
      <description>&lt;P&gt;inputs.conf&lt;BR /&gt;
[script://./bin/test.sh]&lt;BR /&gt;
interval = 60&lt;BR /&gt;
sourcetype = leveltest&lt;BR /&gt;
source= leveltest&lt;BR /&gt;
index = os&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;props.conf:&lt;BR /&gt;
[leveltest]&lt;BR /&gt;
SHOULD_LINEMERGE = False&lt;BR /&gt;
pulldown_type = 1&lt;BR /&gt;
REPORT-level= LEVEL&lt;/P&gt;

&lt;P&gt;transforms.conf:&lt;BR /&gt;
[LEVEL]&lt;BR /&gt;
DELIMS = ","&lt;BR /&gt;
FIELDS =level1, level2, level3, level4, level5, level6, level7, level8 (..need to add level9)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232074#M176566</guid>
      <dc:creator>riotto</dc:creator>
      <dc:date>2020-09-29T11:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: I missed a field in my custom sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232075#M176567</link>
      <description>&lt;P&gt;The data is just integers for each field     202,109,497,3455,223,227,884,334,&lt;STRONG&gt;964&lt;/STRONG&gt; (...level9)&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 19:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-missed-a-field-in-my-custom-sourcetype/m-p/232075#M176567</guid>
      <dc:creator>riotto</dc:creator>
      <dc:date>2016-10-05T19:17:02Z</dc:date>
    </item>
  </channel>
</rss>

