Splunk Search

For multiple, but different field extractions on the same event source, what extraction definition takes precedence?

horsefez
Motivator

Hi fellow Splunkers!

I'm curious to know what field extraction takes precedence if a field extraction is defined by the admin and shared with users and a user by himself created a second extraction slightly different in syntax for the same eventsource.

What extraction-definition takes precedence?

Thanks in advance!
Kind Regards,
pyro_wood

0 Karma
1 Solution

renems
Communicator

Hi Pyro!

In case you have a 'conflicting' extraction, admin will win. In the end it comes down to file precedence. There's a clear explanation of this in the manual, you can find it here:
http://docs.splunk.com/Documentation/Splunk/6.1/admin/Wheretofindtheconfigurationfiles

Specifically your user/admin battle is explained here:
http://dev.splunk.com/view/webframework-developapps/SP-CAAAE6T

However, try to avoid this if you can, because it is not always clear to the user what setting is applied. (could save you a lot of discussion 🙂
Cheers.

View solution in original post

renems
Communicator

Hi Pyro!

In case you have a 'conflicting' extraction, admin will win. In the end it comes down to file precedence. There's a clear explanation of this in the manual, you can find it here:
http://docs.splunk.com/Documentation/Splunk/6.1/admin/Wheretofindtheconfigurationfiles

Specifically your user/admin battle is explained here:
http://dev.splunk.com/view/webframework-developapps/SP-CAAAE6T

However, try to avoid this if you can, because it is not always clear to the user what setting is applied. (could save you a lot of discussion 🙂
Cheers.

horsefez
Motivator

Thank you renems 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...