Getting Data In

Renaming fields in transforms.conf

adrianathome
Communicator

Hello,
I was wondering what would be the impact of renaming fields that have been defined in transforms.conf. More specifically, what happens to data that has already been indexed with the old field names.

Thanks!

Tags (2)
0 Karma
1 Solution

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

View solution in original post

0 Karma

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Are you just renaming some fields where you were using DELIMS or something like that? Splunk allows you to do this at search time so if you change the name, restart Splunk, it will be applied to all of the historical data as well as new data coming in. Keep in mind this could affect any saved searches that already use a particular field name.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...