Getting Data In

Can we have same field extraction for the same sourcetype in 2 different apps?

newbie2tech
Communicator

Hi Team,

Can we have same field extraction for the same sourcetype in 2 different apps? If I already have a Field Extraction based on sourcetype when I try to create another field extraction under different app from the Web GUI for the same pattern in the log I cannot do it. I understand field extractions seem to be at sourcetype level hence we might not be able to.

The challenge that I am having is that I have 2 dashboards which are in 2 different apps, I had created the field extraction in one app, it is shared at "app" level. Now in the other app also I need the same extraction and it is not available. I do not have the permission to make the existing field extraction global hence I was thinking of creating another extraction in the same app.

Other than making it global is there any other option?

Thanks!

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.
0 Karma

newbie2tech
Communicator

Thanks yannK for the answer, this helped me resolve the problem.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...