<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inline field extracted vs Transformation? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323116#M60183</link>
    <description>&lt;P&gt;They are the same except that &lt;CODE&gt;EXTRACT&lt;/CODE&gt; is inlined so only exists in &lt;CODE&gt;props.conf&lt;/CODE&gt; whereas &lt;CODE&gt;REPORT&lt;/CODE&gt; is 2-part with half in &lt;CODE&gt;props.conf&lt;/CODE&gt; and the other half in &lt;CODE&gt;transforms.conf&lt;/CODE&gt;.  If later extractions depend on other extractions, you should definitely use &lt;CODE&gt;REPORT&lt;/CODE&gt; so that you can clearly control which ones happen first.  Also, if you have the same extractions for multiple sourcetypes, it is easier to have a single copy in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; so that any changes/fixes to it are done on 1 line in 1 file instead of on multiple lines in multiple files.  Honestly, &lt;CODE&gt;EXTRACT&lt;/CODE&gt; is lazy; I always do &lt;CODE&gt;REPORT&lt;/CODE&gt;;  I cannot think of any real advantage to &lt;CODE&gt;EXTRACT&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2017 07:32:48 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-02-23T07:32:48Z</dc:date>
    <item>
      <title>Inline field extracted vs Transformation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323115#M60182</link>
      <description>&lt;P&gt;I am walking through the Cisco app and I noticed that there are a lot different ways fields are being extracted. It looks like there are many inline extractions and others referencing a transform, all in the props.conf, (EXTRACT vs REPORT). I have seen bits and pieces on what is the difference is between the two methods, but it still is unclear to me. &lt;/P&gt;

&lt;P&gt;My question is, what are the pros and cons of doing an inline EXTRACT versus doing a transformation and reference it with a REPORT in the props. conf, and vice versa.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 22:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323115#M60182</guid>
      <dc:creator>cmeyers</dc:creator>
      <dc:date>2017-02-22T22:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Inline field extracted vs Transformation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323116#M60183</link>
      <description>&lt;P&gt;They are the same except that &lt;CODE&gt;EXTRACT&lt;/CODE&gt; is inlined so only exists in &lt;CODE&gt;props.conf&lt;/CODE&gt; whereas &lt;CODE&gt;REPORT&lt;/CODE&gt; is 2-part with half in &lt;CODE&gt;props.conf&lt;/CODE&gt; and the other half in &lt;CODE&gt;transforms.conf&lt;/CODE&gt;.  If later extractions depend on other extractions, you should definitely use &lt;CODE&gt;REPORT&lt;/CODE&gt; so that you can clearly control which ones happen first.  Also, if you have the same extractions for multiple sourcetypes, it is easier to have a single copy in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; so that any changes/fixes to it are done on 1 line in 1 file instead of on multiple lines in multiple files.  Honestly, &lt;CODE&gt;EXTRACT&lt;/CODE&gt; is lazy; I always do &lt;CODE&gt;REPORT&lt;/CODE&gt;;  I cannot think of any real advantage to &lt;CODE&gt;EXTRACT&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 07:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323116#M60183</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-23T07:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Inline field extracted vs Transformation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323117#M60184</link>
      <description>&lt;P&gt;Please in better understanding, what is the actual difference between prof.conf and transforms.conf file?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 09:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323117#M60184</guid>
      <dc:creator>rita201</dc:creator>
      <dc:date>2019-04-19T09:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Inline field extracted vs Transformation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323118#M60185</link>
      <description>&lt;P&gt;I never heard of &lt;CODE&gt;prof.conf&lt;/CODE&gt; but in any case, you should ask your own new question.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 05:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Inline-field-extracted-vs-Transformation/m-p/323118#M60185</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-23T05:09:29Z</dc:date>
    </item>
  </channel>
</rss>

