Splunk Search

How can i create a field searchable from client?

felipesewaybric
Contributor

Hi, how i can turn the field client to be reconized on search?

2013-02-07 00:14:14.148056|INFO |VirtualServer | 1| client (id:1004) was added to servergroup 'Normal'(id:7) by client 'eG.Kiros'(id:2)

And the action added to.

So than i can create a table with the clients that mostly added other clients to witch servergorup and other things.

Tags (2)
0 Karma

jbsplunk
Splunk Employee
Splunk Employee

If I understand what you're looking for correctly, I believe the answer to your question is search time field extraction, which is documented here:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsatsearchtime

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...