Splunk Search

View Regex of Extracted Field

vliu2
Explorer

I've written a regex to extract a field. It works perfectly fine, but I wish to copy it down for future use. Is there any way to view the regex of an extracted field?

Tags (2)
0 Karma
1 Solution

vliu2
Explorer

I was looking around and I found the answer here: http://answers.splunk.com/answers/36296/how-to-edit-or-delete-a-custom-field.html

"In Splunk Web, you navigate to the Field extractions page by selecting Manager > Fields > Field extractions."
- Answer by lihong007

View solution in original post

vliu2
Explorer

I was looking around and I found the answer here: http://answers.splunk.com/answers/36296/how-to-edit-or-delete-a-custom-field.html

"In Splunk Web, you navigate to the Field extractions page by selecting Manager > Fields > Field extractions."
- Answer by lihong007

vliu2
Explorer

I gave up trying to deal with the interface, so I just grepped "regex" in my splunk folder instead and found what I was looking for. I'm sure there's a much simpler way to do this.

0 Karma

woodcock
Esteemed Legend

In a way. Take a look at the output from this:

| rest /services/configs/conf-transforms | search MyFieldName
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...