Splunk Search

View Regex of Extracted Field

vliu2
Explorer

I've written a regex to extract a field. It works perfectly fine, but I wish to copy it down for future use. Is there any way to view the regex of an extracted field?

Tags (2)
0 Karma
1 Solution

vliu2
Explorer

I was looking around and I found the answer here: http://answers.splunk.com/answers/36296/how-to-edit-or-delete-a-custom-field.html

"In Splunk Web, you navigate to the Field extractions page by selecting Manager > Fields > Field extractions."
- Answer by lihong007

View solution in original post

vliu2
Explorer

I was looking around and I found the answer here: http://answers.splunk.com/answers/36296/how-to-edit-or-delete-a-custom-field.html

"In Splunk Web, you navigate to the Field extractions page by selecting Manager > Fields > Field extractions."
- Answer by lihong007

vliu2
Explorer

I gave up trying to deal with the interface, so I just grepped "regex" in my splunk folder instead and found what I was looking for. I'm sure there's a much simpler way to do this.

0 Karma

woodcock
Esteemed Legend

In a way. Take a look at the output from this:

| rest /services/configs/conf-transforms | search MyFieldName
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...