Splunk Search

How can I do field extractions from a specific custom event type?

anton_chuvakin
New Member

Why can't I do field extraction from a previously built eventtype? I can limit extraction of sourcetype, but not to eventtype?

I feel like event types and custom field extraction are marriage made in heaven, but somehow splunk UI does not let me do achieve it...

I am sure there is some kinda hack in the conf files to do it... can anybody enlighten me?

0 Karma
1 Solution

Jason
Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

View solution in original post

0 Karma

Jason
Motivator

You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...