Splunk Search

Sharing Field extractions

tb5821
Communicator

I can't for the life of me get one of the search app field extractions to also pick up the same regex (field extraction) on another sourcetype - I've made sure all the permissions are set to global for the extraction, and restarted splunk.

Can anyone offer any help?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Field extractions are relative to sourcetype. You can duplicate the extraction to the new sourcetype and it will work

0 Karma

tb5821
Communicator

There doesn't appear to be an easy way at least within splunk web to clone extractions?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Go to Settings>Fields and find your field. Copy the regular expression, then create new. You should then paste this regex and tie it to your new sourcetype

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Did this work for you?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...