Splunk Search

How I can find field defintion/regex for a particular source type with metadata?

New Member

I like to find out how a particular field is extracted from a given sourcetype. Can I find this via splunk front end using metadata or similar command?

Tags (3)
0 Karma

Esteemed Legend

If I understand you correctly, like this (be sure to swap out PutYourSourcetypeHere and PutYourFieldNameHere with your strings):

| rest/services/configs/conf-props sourcetype="PutYourSourcetypeHere" | eval fields_with_string="," | foreach * [eval fields_with_string=if((like($<<FIELD>>$, "%PutYourFieldNameHere%")), fields_with_string . $<<FIELD>>$ . ",", fields_with_string)] | where fields_with_string!=","
0 Karma

Esteemed Legend

Give a complete example of what you have as data and what you expect to get as a result of your search. I have no idea what you are asking.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!