Skip to main content
Question

is there a way to remove the metric event but still send it to splunk not as a metric

  • March 11, 2025
  • 14 replies
  • 16 views

is there a way to remove the metric event but still send it to splunk not as a metric (if i hover over it says metric event) i was trying to move _value to value and _metric to metric__name

14 replies

Remove __criblMetric field (I think that's the name). That's where the metric data comes from. Does that do what you want ?


How did it turn into a metric event? Was it sent to Stream as such ?


  • Author
  • Employee
  • March 11, 2025

maybe . its causing splunk to not even search it cause i think splunk sees this as a metric even though im trying to push it not to


  • Author
  • Employee
  • March 11, 2025

ya prometheus /write


  • Author
  • Employee
  • March 11, 2025

but alot of these are like data healthcheck up/down


To search for it in splunk it needs to go to a metric index if it's a metric. Remove that field I mentioned and it can go to a regular index and be searched.


  • Author
  • Employee
  • March 11, 2025

__criblMetric right


  • Author
  • Employee
  • March 11, 2025

i tried in the function in pipeline


View it in preview and enable the internal fields to get the exact name. I'm away from keyboard.


  • Author
  • Employee
  • March 11, 2025

ahhh thx :wink:


It's plural at the very least.


  • Author
  • Employee
  • March 11, 2025

__criblEventType:event


  • Author
  • Employee
  • March 11, 2025

__criblMetrics:


  • Author
  • Employee
  • March 11, 2025

cool thanks it worked theres no M there anymore for metrics