Knowledge Management

How to save new field, which created with |cefkv command?

Shyngys_Bolatbe
Engager

How to save new field, which created with |cefkv command?
When I don't use |cefkv command my new fileds disappear.
I want to save fields in index with events

0 Karma

IgorB
Path Finder

New (1.5.0+) versions of CEF Extraction Add-on for Splunk have transforms that can be used to extract custom CEF fields without | cefkv
command

0 Karma

HiroshiSatoh
Champion

It is one of the benefits of Splunk to apply field definitions at search time.
If you really need it, you can also use the collect command to save the search results in the summary index.
You can also define fields if you do not want to use the cefkv command.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...