Splunk Search

Sharing Field extractions

Communicator

I can't for the life of me get one of the search app field extractions to also pick up the same regex (field extraction) on another sourcetype - I've made sure all the permissions are set to global for the extraction, and restarted splunk.

Can anyone offer any help?

0 Karma

SplunkTrust
SplunkTrust

Field extractions are relative to sourcetype. You can duplicate the extraction to the new sourcetype and it will work

0 Karma

Communicator

There doesn't appear to be an easy way at least within splunk web to clone extractions?

0 Karma

SplunkTrust
SplunkTrust

Go to Settings>Fields and find your field. Copy the regular expression, then create new. You should then paste this regex and tie it to your new sourcetype

0 Karma

SplunkTrust
SplunkTrust

Did this work for you?

0 Karma