Hi
I know that splunk automatically creates default fields like host,sourcetype,indexatindextime.And also the splunk provides a option to create any new fields also during indextime.
My r...
...)while DNS logs are only maintained for 1 year ( retention = 1 ).
Everything I have read regarding creating customfieldsatindextime go back to using regex and extracting an existing field i...
...his being said, other documentation at http://www.splunk.com/base/Splexicon:Transform says:
Transforms are always involved in the
setup of customindex-timefield
extractions.
Can s...
...ata and the .tsidx files is made. How are the .tsidx files formed from the event data? When I look at the data models object hierarchy in settings I see the fields that it e...
It seems that it is best to createfieldsat search time as opposed to indextime.!?!? I need to make a field named src be copied/renamed to source_ip. We need to do this to simplify our searches a...
...ickets in a remote system with fields from the alert results. Therefore, in the case of a failure to create a ticket in the remote system, it would be really helpful to know details of the a...
I am trying to extract some json data atindextime. I have found the article about using regular expressions to createcustomfields but regex is not well suited to extracting json. I understand t...
I am working with a custom application that generates log files and I think I need to create a new source type and then during the indexing phase extract the fields.
I know that they say t...
Hi All,
We have some indexes that have suddenly stopped indexing the customfields we had configured on our logs.
There were some changes made to create a new deployment app at the time the p...