Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how to add field extraction to existing default field

$
0
0
I have logs that do not use the default name value format for the "user" field. When I add a field extractor for my user format and name it "user" the default format of "user=" no longer is included in the search. How to I add to the existing field rule rather than replace it?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>