<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field extraction efficiency for transaction command ? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373534#M1139</link>
    <description>&lt;P&gt;HI Splunkers,&lt;/P&gt;

&lt;P&gt;We do have proofpoint logs which we are combining based on the common field with the help of transaction command. &lt;BR /&gt;
Also we don't have proper field extraction in place so we are planning to create one either with splunk extraction options  or with manual regex after the transaction command.&lt;/P&gt;

&lt;P&gt;Which one will be good/efficient way,&lt;BR /&gt;&lt;BR /&gt;
1)  combining the common fields with transaction command and then writing regex as a whole&lt;BR /&gt;
Or 2) Extracting the fields individually  with splunk extraction method and then going with transaction&lt;/P&gt;

&lt;P&gt;Please advice&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2017 06:38:31 GMT</pubDate>
    <dc:creator>renjujacob88</dc:creator>
    <dc:date>2017-10-04T06:38:31Z</dc:date>
    <item>
      <title>Field extraction efficiency for transaction command ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373534#M1139</link>
      <description>&lt;P&gt;HI Splunkers,&lt;/P&gt;

&lt;P&gt;We do have proofpoint logs which we are combining based on the common field with the help of transaction command. &lt;BR /&gt;
Also we don't have proper field extraction in place so we are planning to create one either with splunk extraction options  or with manual regex after the transaction command.&lt;/P&gt;

&lt;P&gt;Which one will be good/efficient way,&lt;BR /&gt;&lt;BR /&gt;
1)  combining the common fields with transaction command and then writing regex as a whole&lt;BR /&gt;
Or 2) Extracting the fields individually  with splunk extraction method and then going with transaction&lt;/P&gt;

&lt;P&gt;Please advice&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 06:38:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373534#M1139</guid>
      <dc:creator>renjujacob88</dc:creator>
      <dc:date>2017-10-04T06:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction efficiency for transaction command ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373535#M1140</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Option #2 is smarter, as you work on the events.&lt;BR /&gt;
But first I would check if transaction can be replaced by the much faster "stats" command, as its a streaming command.&lt;BR /&gt;
In combination with #2 you can pre-filter the data and then add the stats.&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Jens&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 06:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373535#M1140</guid>
      <dc:creator>JensT</dc:creator>
      <dc:date>2017-10-04T06:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction efficiency for transaction command ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373536#M1141</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;you want to use field extractions &lt;STRONG&gt;before&lt;/STRONG&gt; you do your Splunk search with a transaction.&lt;BR /&gt;
Also, if you have fields already, you can as well use the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Stats"&gt;stats&lt;/A&gt; function (or &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Tstats"&gt;tstats&lt;/A&gt; for even faster queries, but no raw data).&lt;BR /&gt;
Stats should be preferred to transactions, it is more efficient.&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 07:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373536#M1141</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-10-04T07:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction efficiency for transaction command ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373537#M1142</link>
      <description>&lt;P&gt;Proofpoint now has a beta app that will allow you report on and visualze your Proofpoint Protection Server and TAP data! Check out the new app here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3727/#/details"&gt;https://splunkbase.splunk.com/app/3727/#/details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Be sure to follow the instructions listed in the details to get all the needed TA's etc that the app needs to work correctly.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 21:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Field-extraction-efficiency-for-transaction-command/m-p/373537#M1142</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2017-10-09T21:41:20Z</dc:date>
    </item>
  </channel>
</rss>

