Splunk Search

How can I do field extractions from a specific custom event type?

anton_chuvakin
New Member

Why can't I do field extraction from a previously built eventtype? I can limit extraction of sourcetype, but not to eventtype?

I feel like event types and custom field extraction are marriage made in heaven, but somehow splunk UI does not let me do achieve it...

I am sure there is some kinda hack in the conf files to do it... can anybody enlighten me?

0 Karma
1 Solution

Jason
Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

View solution in original post

0 Karma

Jason
Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...