I'm trying to make sense of the default access-extractions transform so that I can modify it a bit. I've been nosing around splunk answers and the online Admin Manual. In particular, the "UsetheField...
How do I add a new field extraction using thefieldtransformations I've configured?
We're using Splunk Light Cloud. According to the docs (Knowledge Manager Manual > UsetheField e...
Hi , I have installed Splunk version 7.2.6 in some of the servers and I don't see the type dropdown in one of the servers in thefieldtransformationspage UI . Can you please let m...
I am trying to do the following:
Define a transform 1 in ./apps/search/local/transforms.conf. This creates 4 fields (field1 .... field4)
Define extraction 1 in ./apps/search/local/props.conf....
...ystem
Global | Permissions Enabled Move | Delete
And my fieldtransformations settings page lists the following:
Name Owner App Sharing Status Actions
pfsenseCommonFields
No owner
s...
I have a set of report transforms in an application that I am trying to make global so that fields are extracted when inside the context of the application which defines them and any other a...
...nique_count" field that I always want populated within the Incident Review page under notable events.
By default, it sets count to thefield unique_infections, but I want one field to work for all o...
We are trying to extract both fields and their names from events that have a variable number of elements. We have determined that using a fieldtransformation is the best way to do this, in order t...
After Extracting fields for a source type, and spending a lot of time renaming them. I noticed I missed one. I can go to setting > fields > Field extractions, I can find my saved extraction b...