<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field extractions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759851#M120388</link>
    <description>&lt;P&gt;With Splunk most extractions happen at search time. You can use indexed fields but it's not a recommended good practice. There are some specific use cases when indexed fields are OK but generally you should rather focus on fixing your searches.&lt;/P&gt;&lt;P&gt;And I suspect what you're trying to do is solve a completely different problem than the one you have - you're trying to change your "data infrastructure" while the system load issue is most probably caused by badly written searches (and possibly not properly managed users' workload).&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2026 07:58:00 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2026-04-01T07:58:00Z</dc:date>
    <item>
      <title>Field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759823#M120386</link>
      <description>&lt;P&gt;Hey team,&lt;BR /&gt;If we want to reduce pressure on our Splunk indexers and our data is routing through Cribl, what does Splunk recommend?&lt;BR /&gt;Should all field extractions happen at the Cribl level before data reaches the indexers for any type of data, so the indexers don't need to do any parsing work?&lt;BR /&gt;What's the actual Splunk recommendation here ?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 17:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759823#M120386</guid>
      <dc:creator>spulivarthi700</dc:creator>
      <dc:date>2026-03-31T17:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759847#M120387</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229973"&gt;@spulivarthi700&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the most field extractions are at search time, so the pressure is on Search Heads, not Indexers.&lt;/P&gt;&lt;P&gt;Anyway, in general, you can reduce jobs on Indexers, using one or more intermediate Heavy Forwarders that will parse your data, instead indexers.&lt;/P&gt;&lt;P&gt;but the question is: which Add-On are you using to parse cribl data?&lt;/P&gt;&lt;P&gt;because if you're using the Cribl Decrypt Add-On for Splunk, it hasn't any parsing rule.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 06:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759847#M120387</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-04-01T06:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759851#M120388</link>
      <description>&lt;P&gt;With Splunk most extractions happen at search time. You can use indexed fields but it's not a recommended good practice. There are some specific use cases when indexed fields are OK but generally you should rather focus on fixing your searches.&lt;/P&gt;&lt;P&gt;And I suspect what you're trying to do is solve a completely different problem than the one you have - you're trying to change your "data infrastructure" while the system load issue is most probably caused by badly written searches (and possibly not properly managed users' workload).&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 07:58:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Field-extractions/m-p/759851#M120388</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-04-01T07:58:00Z</dc:date>
    </item>
  </channel>
</rss>

