Getting Data In

How to add field with random value at index time

Micmac
Path Finder

Hello,

I have a quick question :

There is a way at index time to add a field witch could represent something like an event_id ?

Something like this :

FORMAT = event_id::<any_random_value>

At this time I don't know how to generate a unique value to replace

Thanks,

Tags (2)
0 Karma
1 Solution

Ayn
Legend

No. If you're after getting unique id's for events, you could have a look at the _cd field which contains a bucket ID and an address within that bucket. A combination of index and _cd will be unique.

View solution in original post

Ayn
Legend

No. If you're after getting unique id's for events, you could have a look at the _cd field which contains a bucket ID and an address within that bucket. A combination of index and _cd will be unique.

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...