Getting Data In

Renaming fields in transforms.conf

adrianathome
Communicator

Hello,
I was wondering what would be the impact of renaming fields that have been defined in transforms.conf. More specifically, what happens to data that has already been indexed with the old field names.

Thanks!

Tags (2)
0 Karma
1 Solution

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

View solution in original post

0 Karma

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Are you just renaming some fields where you were using DELIMS or something like that? Splunk allows you to do this at search time so if you change the name, restart Splunk, it will be applied to all of the historical data as well as new data coming in. Keep in mind this could affect any saved searches that already use a particular field name.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...