Getting Data In

Renaming fields in transforms.conf

adrianathome
Communicator

Hello,
I was wondering what would be the impact of renaming fields that have been defined in transforms.conf. More specifically, what happens to data that has already been indexed with the old field names.

Thanks!

Tags (2)
0 Karma
1 Solution

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

View solution in original post

0 Karma

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Are you just renaming some fields where you were using DELIMS or something like that? Splunk allows you to do this at search time so if you change the name, restart Splunk, it will be applied to all of the historical data as well as new data coming in. Keep in mind this could affect any saved searches that already use a particular field name.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...