Getting Data In
Highlighted

Can we have same field extraction for the same sourcetype in 2 different apps?

Communicator

Hi Team,

Can we have same field extraction for the same sourcetype in 2 different apps? If I already have a Field Extraction based on sourcetype when I try to create another field extraction under different app from the Web GUI for the same pattern in the log I cannot do it. I understand field extractions seem to be at sourcetype level hence we might not be able to.

The challenge that I am having is that I have 2 dashboards which are in 2 different apps, I had created the field extraction in one app, it is shared at "app" level. Now in the other app also I need the same extraction and it is not available. I do not have the permission to make the existing field extraction global hence I was thinking of creating another extraction in the same app.

Other than making it global is there any other option?

Thanks!

0 Karma
Highlighted

Re: Can we have same field extraction for the same sourcetype in 2 different apps?

Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.

View solution in original post

0 Karma
Highlighted

Re: Can we have same field extraction for the same sourcetype in 2 different apps?

Communicator

Thanks yannK for the answer, this helped me resolve the problem.

0 Karma