<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does INDEXED_EXTRACTIONS imply index fields for all the fields? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758178#M120225</link>
    <description>&lt;P&gt;I just set&amp;nbsp;INDEXED_EXTRACTIONS&lt;SPAN&gt;&amp;nbsp;= CSV for a large data ingestion sourcetype, and validating with tstats, and it seems that all the fields are indexed fields, is it true in general including for JSON? Is there any way around it of not making them indexed fields?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Feb 2026 14:57:11 GMT</pubDate>
    <dc:creator>spl_aficionado</dc:creator>
    <dc:date>2026-02-09T14:57:11Z</dc:date>
    <item>
      <title>Does INDEXED_EXTRACTIONS imply index fields for all the fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758178#M120225</link>
      <description>&lt;P&gt;I just set&amp;nbsp;INDEXED_EXTRACTIONS&lt;SPAN&gt;&amp;nbsp;= CSV for a large data ingestion sourcetype, and validating with tstats, and it seems that all the fields are indexed fields, is it true in general including for JSON? Is there any way around it of not making them indexed fields?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 14:57:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758178#M120225</guid>
      <dc:creator>spl_aficionado</dc:creator>
      <dc:date>2026-02-09T14:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does INDEXED_EXTRACTIONS imply index fields for all the fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758179#M120226</link>
      <description>&lt;P&gt;Yes, setting &lt;FONT face="courier new,courier"&gt;INDEXED_EXTRACTIONS=JSON&lt;/FONT&gt; will index all of the fields in each event.&amp;nbsp; There is no way to prevent that, which is why many recommend against using &lt;FONT face="courier new,courier"&gt;INDEXED_EXTRACTIONS&lt;/FONT&gt; at all.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 14:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758179#M120226</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-02-09T14:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does INDEXED_EXTRACTIONS imply index fields for all the fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758181#M120227</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270618"&gt;@spl_aficionado&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;using INDEXED_EXTRACTIONS=csv, you extract all the fields, but they aren't indexed time fields.&lt;/P&gt;&lt;P&gt;If you mead extracted fields, yes all fields are extracted, if you mean indexed fields, they aren't indexed fields.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 15:07:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-INDEXED-EXTRACTIONS-imply-index-fields-for-all-the-fields/m-p/758181#M120227</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-02-09T15:07:22Z</dc:date>
    </item>
  </channel>
</rss>

