Splunk Search

edit existing field extraction splunk ui

pdevosceazure
Path Finder

After Extracting fields for a source type, and spending a lot of time renaming them. I noticed I missed one.

I can go to setting > fields > Field extractions,

I can find my saved extraction by name. But is there any way to edit it?

 

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @pdevosceazure,

You need to go Fields » Field transformations page and find "dsa-unix" to edit fields.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @pdevosceazure,

You need to go Fields » Field transformations page and find "dsa-unix" to edit fields.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

pdevosceazure
Path Finder

Brilliant thank, this is it.

Much appreciated

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is resolved, then please click the "Accept as Solution" button to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Clicking on the name of the extraction should bring up a dialog box that lets you modify it.

---
If this reply helps you, Karma would be appreciated.

pdevosceazure
Path Finder

Thanks, However, edition just let me change the name, not editing fields

1.jpg

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...