Splunk Search

can i replace the _raw data with my own data ??

rakesh_498115
Motivator

HI..

can i replace the _raw data value with my default data value only for the display purpose only ??

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Ayn
Legend

Yes, you can.

Ayn
Legend

...or if you just want to change how it's displayed, but leave the value intact if you have other things using that in your search, use fieldformat.

... | fieldformat _raw=<yourdata>
0 Karma

Ayn
Legend

... | eval _raw=

0 Karma

rakesh_498115
Motivator

can you give me the command or query for doin that ??

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...