Splunk Search

regex for Apps

fuster_j
Path Finder

I'm looking for the regex for extracted fields in a custom built app. I cannot find them in any props.conf and transforms.conf. Are they stored in different location for Apps?

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

Depending on how the app is built they could also be stored as rex statements inside saved searches used by the app. If you wrote the app, you would probably know that already 🙂

Kristian

0 Karma

Ayn
Legend

No, they go in props.conf / transforms.conf in either the app's default or local directory.

Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...