Splunk Enterprise Security

How to see newly created calculated field/field alias/field extraction in the logs ?


Hi All,

I have created a newly created field/field alias/field extraction with GLOBAL Permissions.

Example | eval test="MyApp"

This works fine when I use it in search but when I save it as calculated field it doesn't show up.  I refreshed 10 times even cleared browser cache and logged back in. Still same issue. We don't see newly created KO in the logs but can run those in searches.

Any inputs or help 

@woodcock @Splunkers 2022 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...