I'm trying to make sense of the default access-extractions transform so that I can modify it a bit. I've been nosing around splunk answers and the online Admin Manual. In particular, the "UsetheField...
How do I add a new field extraction using thefieldtransformations I've configured?
We're using Splunk Light Cloud. According to the docs (Knowledge Manager Manual > UsetheField e...
Hi , I have installed Splunk version 7.2.6 in some of the servers and I don't see the type dropdown in one of the servers in thefieldtransformationspage UI . Can you please let m...
I am trying to do the following:
Define a transform 1 in ./apps/search/local/transforms.conf. This creates 4 fields (field1 .... field4)
Define extraction 1 in ./apps/search/local/props.conf....
...ystem
Global | Permissions Enabled Move | Delete
And my fieldtransformations settings page lists the following:
Name Owner App Sharing Status Actions
pfsenseCommonFields
No owner
s...
I have a set of report transforms in an application that I am trying to make global so that fields are extracted when inside the context of the application which defines them and any other a...
We are trying to extract both fields and their names from events that have a variable number of elements. We have determined that using a fieldtransformation is the best way to do this, in order t...
...nique_count" field that I always want populated within the Incident Review page under notable events.
By default, it sets count to thefield unique_infections, but I want one field to work for all o...
After Extracting fields for a source type, and spending a lot of time renaming them. I noticed I missed one. I can go to setting > fields > Field extractions, I can find my saved extraction b...