<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: field extraction in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526766#M88849</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You could use walklex command to get list of index time extractions. Rest of fields are search time extracted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| walklex index=main type=field
| dedup field
| table field&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Walklex" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Walklex&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 07:33:47 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-10-28T07:33:47Z</dc:date>
    <item>
      <title>field extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526752#M88845</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How to find whether a field is extracted at index time (or) search time?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 05:51:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526752#M88845</guid>
      <dc:creator>VijaySrrie</dc:creator>
      <dc:date>2020-10-28T05:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526766#M88849</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You could use walklex command to get list of index time extractions. Rest of fields are search time extracted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| walklex index=main type=field
| dedup field
| table field&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Walklex" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Walklex&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 07:33:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526766#M88849</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-28T07:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526785#M88853</link>
      <description>&lt;P&gt;I am getting below error in Splunk PROD&lt;/P&gt;&lt;P&gt;Unknown search command 'walklex'.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 08:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526785#M88853</guid>
      <dc:creator>VijaySrrie</dc:creator>
      <dc:date>2020-10-28T08:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526795#M88858</link>
      <description>HI&lt;BR /&gt;this command has come on version 7.3.0. If you have older version then it's time to update anyhow as 7.2 is quite soon out of support.&lt;BR /&gt;Before that you could search from answers what are other ways to get this information.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Wed, 28 Oct 2020 09:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/field-extraction/m-p/526795#M88858</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-28T09:29:29Z</dc:date>
    </item>
  </channel>
</rss>

