Knowledge Management

How to save new field, which created with |cefkv command?

Shyngys_Bolatbe
Engager

How to save new field, which created with |cefkv command?
When I don't use |cefkv command my new fileds disappear.
I want to save fields in index with events

0 Karma

IgorB
Path Finder

New (1.5.0+) versions of CEF Extraction Add-on for Splunk have transforms that can be used to extract custom CEF fields without | cefkv
command

0 Karma

HiroshiSatoh
Champion

It is one of the benefits of Splunk to apply field definitions at search time.
If you really need it, you can also use the collect command to save the search results in the summary index.
You can also define fields if you do not want to use the cefkv command.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...