Getting Data In

Why is a field which doesn't exist in _raw data being added to an index?

vn_g
Path Finder

Eg :

index = userinformation

_raw doesnt have any field or value related to field "ue".

But "ue" is being shown in Interesting Fields.
ue = abc@splunk.com
ue = xyz@splunk.com

So my questioning is what is generating this field to exist in the index?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Look for INGEST_EVAL statements in transforms.conf.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

mykol_j
Explorer

forgive my ignorance, but I don't understand the answer.

Do I look on my indexers (all 3 in my case) for this?

What am I looking for?

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!