Getting Data In

In Splunk Cloud, once you have indexed extractions, you're stuck.. forever

splunkjas1
Path Finder

Has anyone ever been able to select none in the indexed extractions dropdown once you already have something else selected? I have a sourcetype with csv selected and every time I choose none, it resets to csv on save. Oh, and you can't delete sourcetypes and start over.

0 Karma

splunkjas1
Path Finder

After much trial and error, the only thing that seems to work is setting INDEXED_EXTRACTIONS to a space.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...