Splunk Enterprise Security

How to see newly created calculated field/field alias/field extraction in the logs ?

sohailmohammed
Explorer

Hi All,

I have created a newly created field/field alias/field extraction with GLOBAL Permissions.

Example | eval test="MyApp"

This works fine when I use it in search but when I save it as calculated field it doesn't show up.  I refreshed 10 times even cleared browser cache and logged back in. Still same issue. We don't see newly created KO in the logs but can run those in searches.

Any inputs or help 

@woodcock @Splunkers 2022 

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...