Splunk Search

Cut Fields of log data file

rafamss
Contributor

Hi guys,

I'll appreciate your help for my question. Well, I have a data file that has ten fields and I need cut only two and only two fields can be indexed. What do I do ?

Thanks!

Rafael Martins

0 Karma
1 Solution

kristian_kolb
Ultra Champion

Please provide some samples for more explicit help, but I think you could have a look here, where the process of selectively discarding parts of an event is described.

http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Anonymizedatausingconfigurationfiles

/k

View solution in original post

0 Karma

kristian_kolb
Ultra Champion

Please provide some samples for more explicit help, but I think you could have a look here, where the process of selectively discarding parts of an event is described.

http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Anonymizedatausingconfigurationfiles

/k

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...