Splunk Enterprise

Is there any possible to modify raw data in Splunk

jenniferhao
Explorer

hello,

we have some raw data with one field wrong from April. But we cannot reload data from the source. Is there any way that we can modify only one field? for example:

_time  id  name  value:

20210406 1  "SMT" 60        to be   20210406 1  "Node" 60

20210416 100  "SMT" 80   to be   20210416 100  "Node" 80

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Ingested data is immutable.  There is no way to change, modify, or edit data once it's in a Splunk index.

The best you can do is add logic to your queries to replace "SMT" with "Node" in the name field.  Once the April data expires you can remove that logic.

---
If this reply helps you, Karma would be appreciated.

jenniferhao
Explorer

Thanks. But the issue not all of "SMT" in April was wrong. Only part of them need to be update. Anyway, thanks for your reply.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...