Getting Data In

How find index-time field extractions.

adamsmith47
Communicator

Hello all,

Our environment has some custom index-time field extractions we find to be very useful (yes, I know Splunk doesn't recommend this). Though due to the possible performance implications of this practice, I want to be 100% confident I know where all index-time fields exist in our indexes.

At first, I thought this would be easy, throw a |tstats command together... when it dawned on me I have no idea how to do this.

So, if anyone can think of how to get a list of indexes/sources/sourcetypes which contain non-standard index-time field extractions, that'd be a life-saver!

Thanks for any help.

0 Karma

martynoconnor
Communicator

| tstats count where index=yourindex by yourindexedfield

If it works, you're in business, if not... sadly no.

You could also do a conventional search like

index=foo fieldname::value

If that works, it's an indexed field.

esix_splunk
Splunk Employee
Splunk Employee

Ill add to this that you need to make sure you have the correct configurations deployed on your SH for indexed fields for them to be properly recognized via *fields.conf ( https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Configureindex-timefieldextraction)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...