Splunk Search

Duplicate Extracted Fields

clpsplunk
New Member

I have a problem with Protocol and protocol, Host and host, Device and Device_IP. I extracted and named them manually but don't like the results. Can I delete one and keep the other?

Thanks

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Sure, they should reside in Settings -> Fields -> Field Extractions and have delete links.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...