Splunk Search

Field extration based on Event Type

New Member

Hi I have created a custom Event type and I would like to perform some field extraction based on the new event type, but I can't do it. I can oly extract based on the Host, Source and sourcetype

Tags (2)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

Yes, host source sourcetype only.

See http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf - specifically, the section explaining .

View solution in original post

0 Karma

Explorer

Eventtype produced under the conditions of a particular field >>

AS-IS

index=AAA (keyworld1 OR kewyorld2) AND (keyworld3)

To-BE

index=AAA (SpecificField="keyworld1" OR SpecificField="kewyorld2") AND (Specific_Field="keyworld3")

0 Karma

SplunkTrust
SplunkTrust

Yes, host source sourcetype only.

See http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf - specifically, the section explaining .

View solution in original post

0 Karma