Splunk Search

Managing new field extractions on the fly

aohls
Contributor

Looking for insight as to how people manage when you have macros and other knowledge objects and new logs can get added without us knowing. We have a number of marcos and then a new log is added; which we do not always know, we can miss items due to the filtering within the macro/search on a field extraction. The logging standards are good but we just have new items. 

 

I was thinking of doing a check of the field extractions to find differences through a quick search or some type of lookup; which can then be used to get dashboard items easier which we use a search for now.

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
The best practice is to define integration/ onboard process which needs to follow before logs can present on splunk.
Another way is create alert or dashboard where you could found new host + source which have added without your knowledge.
r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust
The best practice is to define integration/ onboard process which needs to follow before logs can present on splunk.
Another way is create alert or dashboard where you could found new host + source which have added without your knowledge.
r. Ismo

aohls
Contributor

That is what should happen, unfortunately it doesn't always. I setup a morning report to present anything new to me.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...