- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to add custom field to event?

mnoster
Engager
01-15-2019
07:32 PM
I want to add custom fields to specific index and have them log accordingly.
Currently there are only a few default fields such as "host", "index", "sourcetype", etc...
Not sure if this is the best place to add additional data or not.
How can I add more fields?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

woodcock
Esteemed Legend
01-16-2019
10:16 AM
There is a ton of documentation on this. Start here:
https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ExtractfieldsinteractivelywithIFX
