Splunk Search

View Regex of Extracted Field

vliu2
Explorer

I've written a regex to extract a field. It works perfectly fine, but I wish to copy it down for future use. Is there any way to view the regex of an extracted field?

Tags (2)
0 Karma
1 Solution

vliu2
Explorer

I was looking around and I found the answer here: http://answers.splunk.com/answers/36296/how-to-edit-or-delete-a-custom-field.html

"In Splunk Web, you navigate to the Field extractions page by selecting Manager > Fields > Field extractions."
- Answer by lihong007

View solution in original post

vliu2
Explorer

I was looking around and I found the answer here: http://answers.splunk.com/answers/36296/how-to-edit-or-delete-a-custom-field.html

"In Splunk Web, you navigate to the Field extractions page by selecting Manager > Fields > Field extractions."
- Answer by lihong007

vliu2
Explorer

I gave up trying to deal with the interface, so I just grepped "regex" in my splunk folder instead and found what I was looking for. I'm sure there's a much simpler way to do this.

0 Karma

woodcock
Esteemed Legend

In a way. Take a look at the output from this:

| rest /services/configs/conf-transforms | search MyFieldName
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...