Getting Data In

Why is a field which doesn't exist in _raw data being added to an index?

vn_g
Path Finder

Eg :

index = userinformation

_raw doesnt have any field or value related to field "ue".

But "ue" is being shown in Interesting Fields.
ue = abc@splunk.com
ue = xyz@splunk.com

So my questioning is what is generating this field to exist in the index?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Look for INGEST_EVAL statements in transforms.conf.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mykol_j
Communicator

forgive my ignorance, but I don't understand the answer.

Do I look on my indexers (all 3 in my case) for this?

What am I looking for?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...