Splunk Search

How I can find field defintion/regex for a particular source type with metadata?

aartist
New Member

I like to find out how a particular field is extracted from a given sourcetype. Can I find this via splunk front end using metadata or similar command?
<P>
Thanks.

Tags (3)
0 Karma

woodcock
Esteemed Legend

If I understand you correctly, like this (be sure to swap out PutYourSourcetypeHere and PutYourFieldNameHere with your strings):

| rest/services/configs/conf-props sourcetype="PutYourSourcetypeHere" | eval fields_with_string="," | foreach * [eval fields_with_string=if((like($<<FIELD>>$, "%PutYourFieldNameHere%")), fields_with_string . $<<FIELD>>$ . ",", fields_with_string)] | where fields_with_string!=","
0 Karma

woodcock
Esteemed Legend

Give a complete example of what you have as data and what you expect to get as a result of your search. I have no idea what you are asking.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...