Knowledge Management

How to save new field, which created with |cefkv command?

Shyngys_Bolatbe
Engager

How to save new field, which created with |cefkv command?
When I don't use |cefkv command my new fileds disappear.
I want to save fields in index with events

0 Karma

IgorB
Path Finder

New (1.5.0+) versions of CEF Extraction Add-on for Splunk have transforms that can be used to extract custom CEF fields without | cefkv
command

0 Karma

HiroshiSatoh
Champion

It is one of the benefits of Splunk to apply field definitions at search time.
If you really need it, you can also use the collect command to save the search results in the summary index.
You can also define fields if you do not want to use the cefkv command.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...