Splunk Search

Did newer versions of Splunk stop renaming fields with periods to underscores?

alexl1
Path Finder

hi,

Did newer versions of Splunk stop renaming fields with periods to underscores? This used to work, but does not work anymore after a couple of upgrades.

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi alexl1,

as stated in the docs http://docs.splunk.com/Documentation/Splunk/6.4.1/Knowledge/Managesearch-timefieldextractions still is still done by default:

Splunk Enterprise applies the following "key cleaning" rules to all extracted fields, either by default or through a custom configuration:

 - All characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).
 - All leading underscores and 0-9 characters are removed from extracted field names.
To disable this behavior for a specific field extraction, you have to manually modify both props.conf and transforms.conf. 

Check with btool if any of your props.conf and transforms.conf in some app is disabling this function.

Hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi alexl1,

as stated in the docs http://docs.splunk.com/Documentation/Splunk/6.4.1/Knowledge/Managesearch-timefieldextractions still is still done by default:

Splunk Enterprise applies the following "key cleaning" rules to all extracted fields, either by default or through a custom configuration:

 - All characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).
 - All leading underscores and 0-9 characters are removed from extracted field names.
To disable this behavior for a specific field extraction, you have to manually modify both props.conf and transforms.conf. 

Check with btool if any of your props.conf and transforms.conf in some app is disabling this function.

Hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...