Splunk Search

Is there a way to tell if a field is an index time field (vs a search time field)?

chris
Motivator

Hi

is there a way (in Splunk Web or from the CLI) to see if a field was extracted at search time or at index time?

Thanks

Chris

Tags (2)
0 Karma
1 Solution

DTERM
Contributor

I don't believe this is possible.

View solution in original post

0 Karma

DTERM
Contributor

I don't believe this is possible.

0 Karma

chris
Motivator

I guess you're right

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...