Using the admin interface to build a field

Taking our pattern from the previous example, we can build the configuration to wire up this extract.

First, click on Settings in the upper menu bar. From there, select Fields. The Fields section contains everything, funnily enough, about fields.

Here you can view, edit, and set permissions on field extractions. Define event workflow actions, field aliases, and even rename source types.

For now, we're interested in Field extractions.

After clicking on Add new to the right of Field extractions, or on the New button after clicking on Field extractions, we are presented with the interface for creating a new field:

Now, we step through the fields:

  • Destination app lets us choose the app where this extraction ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.