Getting Data In

Renaming fields in transforms.conf

adrianathome
Communicator

Hello,
I was wondering what would be the impact of renaming fields that have been defined in transforms.conf. More specifically, what happens to data that has already been indexed with the old field names.

Thanks!

Tags (2)
0 Karma
1 Solution

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

View solution in original post

0 Karma

adrianathome
Communicator

No impact. The fields applied to all the data that was previously indexed. Thanks sdaniels.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Are you just renaming some fields where you were using DELIMS or something like that? Splunk allows you to do this at search time so if you change the name, restart Splunk, it will be applied to all of the historical data as well as new data coming in. Keep in mind this could affect any saved searches that already use a particular field name.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...