Splunk Search
Highlighted

How can I do field extractions from a specific custom event type?

New Member

Why can't I do field extraction from a previously built eventtype? I can limit extraction of sourcetype, but not to eventtype?

I feel like event types and custom field extraction are marriage made in heaven, but somehow splunk UI does not let me do achieve it...

I am sure there is some kinda hack in the conf files to do it... can anybody enlighten me?

0 Karma

Re: How can I do field extractions from a specific custom event type?

Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

View solution in original post

0 Karma