Getting Data In

Can we have same field extraction for the same sourcetype in 2 different apps?

newbie2tech
Communicator

Hi Team,

Can we have same field extraction for the same sourcetype in 2 different apps? If I already have a Field Extraction based on sourcetype when I try to create another field extraction under different app from the Web GUI for the same pattern in the log I cannot do it. I understand field extractions seem to be at sourcetype level hence we might not be able to.

The challenge that I am having is that I have 2 dashboards which are in 2 different apps, I had created the field extraction in one app, it is shared at "app" level. Now in the other app also I need the same extraction and it is not available. I do not have the permission to make the existing field extraction global hence I was thinking of creating another extraction in the same app.

Other than making it global is there any other option?

Thanks!

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.
0 Karma

newbie2tech
Communicator

Thanks yannK for the answer, this helped me resolve the problem.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...