Getting Data In

Can we have same field extraction for the same sourcetype in 2 different apps?

newbie2tech
Communicator

Hi Team,

Can we have same field extraction for the same sourcetype in 2 different apps? If I already have a Field Extraction based on sourcetype when I try to create another field extraction under different app from the Web GUI for the same pattern in the log I cannot do it. I understand field extractions seem to be at sourcetype level hence we might not be able to.

The challenge that I am having is that I have 2 dashboards which are in 2 different apps, I had created the field extraction in one app, it is shared at "app" level. Now in the other app also I need the same extraction and it is not available. I do not have the permission to make the existing field extraction global hence I was thinking of creating another extraction in the same app.

Other than making it global is there any other option?

Thanks!

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.
0 Karma

newbie2tech
Communicator

Thanks yannK for the answer, this helped me resolve the problem.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...