Getting Data In

Renaming fields in transforms.conf

adrianathome
Communicator

Hello,
I was wondering what would be the impact of renaming fields that have been defined in transforms.conf. More specifically, what happens to data that has already been indexed with the old field names.

Thanks!

Tags (2)
0 Karma
1 Solution

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

View solution in original post

0 Karma

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Are you just renaming some fields where you were using DELIMS or something like that? Splunk allows you to do this at search time so if you change the name, restart Splunk, it will be applied to all of the historical data as well as new data coming in. Keep in mind this could affect any saved searches that already use a particular field name.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...