Splunk Search

Managing new field extractions on the fly

aohls
Contributor

Looking for insight as to how people manage when you have macros and other knowledge objects and new logs can get added without us knowing. We have a number of marcos and then a new log is added; which we do not always know, we can miss items due to the filtering within the macro/search on a field extraction. The logging standards are good but we just have new items. 

 

I was thinking of doing a check of the field extractions to find differences through a quick search or some type of lookup; which can then be used to get dashboard items easier which we use a search for now.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
The best practice is to define integration/ onboard process which needs to follow before logs can present on splunk.
Another way is create alert or dashboard where you could found new host + source which have added without your knowledge.
r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust
The best practice is to define integration/ onboard process which needs to follow before logs can present on splunk.
Another way is create alert or dashboard where you could found new host + source which have added without your knowledge.
r. Ismo

aohls
Contributor

That is what should happen, unfortunately it doesn't always. I setup a morning report to present anything new to me.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...