<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sharing Field extractions in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304620#M91560</link>
    <description>&lt;P&gt;Field extractions are relative to sourcetype. You can duplicate the extraction to the new sourcetype and it will work&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2018 14:39:31 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2018-02-22T14:39:31Z</dc:date>
    <item>
      <title>Sharing Field extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304619#M91559</link>
      <description>&lt;P&gt;I can't for the life of me get one of the search app field extractions to also pick up the same regex (field extraction) on another sourcetype - I've made sure all the permissions are set to global for the extraction, and restarted splunk.&lt;/P&gt;

&lt;P&gt;Can anyone offer any help?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 13:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304619#M91559</guid>
      <dc:creator>tb5821</dc:creator>
      <dc:date>2018-02-22T13:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sharing Field extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304620#M91560</link>
      <description>&lt;P&gt;Field extractions are relative to sourcetype. You can duplicate the extraction to the new sourcetype and it will work&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 14:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304620#M91560</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-02-22T14:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sharing Field extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304621#M91561</link>
      <description>&lt;P&gt;There doesn't appear to be an easy way at least within splunk web to clone extractions? &lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 14:45:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304621#M91561</guid>
      <dc:creator>tb5821</dc:creator>
      <dc:date>2018-02-22T14:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sharing Field extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304622#M91562</link>
      <description>&lt;P&gt;Go to &lt;CODE&gt;Settings&amp;gt;Fields&lt;/CODE&gt; and find your field. Copy the regular expression, then create new. You should then paste this regex and tie it to your new sourcetype &lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 14:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304622#M91562</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-02-22T14:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sharing Field extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304623#M91563</link>
      <description>&lt;P&gt;Did this work for you?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 14:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sharing-Field-extractions/m-p/304623#M91563</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-02-27T14:28:30Z</dc:date>
    </item>
  </channel>
</rss>

