Splunk Search
Highlighted

how to search for index time extracted fields added to metadata

Contributor

I need only fields that are extracted during index_time which are added to _meta. How to search for them so that search is faster

0 Karma
Highlighted

Re: how to search for index time extracted fields added to metadata

Legend

Hi ankithreddy777,
use | metasearch before your search condition.
see http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Metasearch
Bye.
Giuseppe

Highlighted

Re: how to search for index time extracted fields added to metadata

SplunkTrust
SplunkTrust

Try something like this. This should give a list of metadata fields available for an index-sourcetype combination.

| metasearch index=YourIndex sourcetype=YourSourceType | head 1 | transpose