Splunk Search

How can I do field extractions from a specific custom event type?

anton_chuvakin
New Member

Why can't I do field extraction from a previously built eventtype? I can limit extraction of sourcetype, but not to eventtype?

I feel like event types and custom field extraction are marriage made in heaven, but somehow splunk UI does not let me do achieve it...

I am sure there is some kinda hack in the conf files to do it... can anybody enlighten me?

0 Karma
1 Solution

Jason
Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

View solution in original post

0 Karma

Jason
Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...