I'm new to Splunk and I would like to know how to change indexing fields which Spluck automaticly assigned (i.e. rename the field, remove or add). I really appreciate some directions
You can specify fields in your props.conf file
# The following stanza extracts an ip address from _raw [my_sourcetype] EXTRACT-extract_ip = (?
Here is the documentation link