Actually, you don't need to edit config files to do this. In the Splunk UI, under Settings->Fields you will see an entry for "Calculated fields". If you create the same definition that you put into your search there, assign it to your sourcetype in question and share it globally, the field will be automatically calculated whenever you search for that sourcetype.
... View more