Getting Data In

Can we have same field extraction for the same sourcetype in 2 different apps?

newbie2tech
Communicator

Hi Team,

Can we have same field extraction for the same sourcetype in 2 different apps? If I already have a Field Extraction based on sourcetype when I try to create another field extraction under different app from the Web GUI for the same pattern in the log I cannot do it. I understand field extractions seem to be at sourcetype level hence we might not be able to.

The challenge that I am having is that I have 2 dashboards which are in 2 different apps, I had created the field extraction in one app, it is shared at "app" level. Now in the other app also I need the same extraction and it is not available. I do not have the permission to make the existing field extraction global hence I was thinking of creating another extraction in the same app.

Other than making it global is there any other option?

Thanks!

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

As long as you make sure that the apps extractions are not global, then it's possible to have fields with the same name in different app context.

  • ultimately, the TRANSFORMS-name or REPORT-name or EXTRACT-name stanza in props may have to have different names (to avoid confusions between apps, otherwise precedence will apply )
  • if one of your app is global and you have 2 identical field names, then the 2 fields extractions may both apply, then the stanza should apply in alphabetical order, and the last one will overwrite the field.
  • finally if one of your field is an INDEXEDTIME_EXTRACTION, or indextime transforms, then you may end up with multivalue fields, with 2 values.
0 Karma

newbie2tech
Communicator

Thanks yannK for the answer, this helped me resolve the problem.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...