Previously I was searching and extracting field at search time by explicitly specifying
rex command. Now, I want to do the same thing but I want splunk to understand that I want "that" field extracted when relevant data is searched. How can I do using manager? ( Also, I do wish to keep it general i.e. not based on any source or something similar. )
My previous query was -
* | rex "(?<authentication_type>(?i)(password))"
Now, I want to do something like this -
Manager -> Fields -> Field Extractions
You can basically paste a rex regex into the new extraction. However, an extraction must target a source, sourcetype, or host. I suppose you could set the source value to "*" though.
Reading up on props.conf will give you some insight into this: http://www.splunk.com/base/Documentation/latest/admin/Propsconf