Splunk Search

What value of dest_key should be used for custom field extractions?

Contributor

During index time field extractions, what value of DEST_KEY should be used for custom field extractions as there is no default?

0 Karma
1 Solution

Revered Legend

If you're adding a custom field extraction as index time (not overwriting existing metadata/default fields like host, source, sourcetype, _raw), and setting WRITE_META = true and providing custom field name in REGEX or FORMAT attribute, then DEST_KEY is not required.

View solution in original post

Revered Legend

If you're adding a custom field extraction as index time (not overwriting existing metadata/default fields like host, source, sourcetype, _raw), and setting WRITE_META = true and providing custom field name in REGEX or FORMAT attribute, then DEST_KEY is not required.

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!