setfields
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
setfields
Synopsis
Sets the field values for all results to a common value.
Syntax
setfields <setfields-arg>, ...
Arguments
- setfields-arg
- Syntax: string="<string>"
- Description: A key-value pair with quoted value. Standard key cleaning will be performed, ie all non-alphanumeric characters will be replaced with '_' and leading '_' will be removed.
Description
Sets the value of the given fields to the specified values for each event in the result set. Delimit multiple definitions with commas. Missing fields are added, present fields are overwritten.
Examples
Example 1: Specify a value for the ip and foo fields.
... | setfields ip="10.10.10.10", foo="foo bar"See also
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.