Splunk Search

What value of dest_key should be used for custom field extractions?

Contributor

During index time field extractions, what value of DEST_KEY should be used for custom field extractions as there is no default?

0 Karma
1 Solution

SplunkTrust
SplunkTrust

If you're adding a custom field extraction as index time (not overwriting existing metadata/default fields like host, source, sourcetype, raw), and setting WRITEMETA = true and providing custom field name in REGEX or FORMAT attribute, then DEST_KEY is not required.

View solution in original post

SplunkTrust
SplunkTrust

If you're adding a custom field extraction as index time (not overwriting existing metadata/default fields like host, source, sourcetype, raw), and setting WRITEMETA = true and providing custom field name in REGEX or FORMAT attribute, then DEST_KEY is not required.

View solution in original post