Splunk Search

How to add new field in existing index

jadengoho
Builder

I have a index that have 2 fields only
index="TRIAL_INDEX" fields: sample1, sample2

And i will make a new field by
index="TRIAL_INDEX"
| eval sample3= sample1+sample2

What i want is that sample3 would add to the index , so the next time i search it will appear anywhere.

Tags (1)
0 Karma

mayurr98
Super Champion

hey try this

go to Fields » Calculated fields » Add new
Put Name: sample3
Eval Expression : sample1+sample2

let me know if this helps!

0 Karma

jadengoho
Builder

Yes it is helpful , but is there a way that it will be triggered when a BUTTON CLICK in the dashboard ? or in the SPL itself ?

0 Karma

mayurr98
Super Champion

I do not know but this is achievable by js on a dashboard but then it will not reflect in a raw data.This is the only method I think to reflect in a raw data by default.

0 Karma

cmerriman
Super Champion

you're wanting sample3 always in your results without having to add that eval statement?

0 Karma

jadengoho
Builder

what i want is the sample1, sample2, sample3 would be in the index .
After i eval it i like it to be insert to the index , if that is possible .

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...