Hi alexl1,
as stated in the docs http://docs.splunk.com/Documentation/Splunk/6.4.1/Knowledge/Managesearch-timefieldextractions still is still done by default:
Splunk Enterprise applies the following "key cleaning" rules to all extracted fields, either by default or through a custom configuration:
- All characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).
- All leading underscores and 0-9 characters are removed from extracted field names.
To disable this behavior for a specific field extraction, you have to manually modify both props.conf and transforms.conf.
Check with btool
if any of your props.conf
and transforms.conf
in some app is disabling this function.
Hope this helps ...
cheers, MuS
Hi alexl1,
as stated in the docs http://docs.splunk.com/Documentation/Splunk/6.4.1/Knowledge/Managesearch-timefieldextractions still is still done by default:
Splunk Enterprise applies the following "key cleaning" rules to all extracted fields, either by default or through a custom configuration:
- All characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).
- All leading underscores and 0-9 characters are removed from extracted field names.
To disable this behavior for a specific field extraction, you have to manually modify both props.conf and transforms.conf.
Check with btool
if any of your props.conf
and transforms.conf
in some app is disabling this function.
Hope this helps ...
cheers, MuS