<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is an interesting field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417960#M169214</link>
    <description>&lt;P&gt;@vipmakka, go through &lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html"&gt;Splunk Fundamentals 1&lt;/A&gt; free course where module 3 talks about this in details. &lt;/P&gt;

&lt;P&gt;Once you complete the self paced e-learning course you are eligible to take an exam and become Splunk Certified User as well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 May 2018 18:56:01 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2018-05-24T18:56:01Z</dc:date>
    <item>
      <title>What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417956#M169210</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;sourcetype=access_combined | fields clientip host action status
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;All Fields&lt;BR /&gt;
Selected Fields&lt;BR /&gt;
aaction 5&lt;BR /&gt;
ahost 3&lt;BR /&gt;
Interesting Fields&lt;BR /&gt;
aclientip 100+&lt;/P&gt;

&lt;H1&gt;status 9&lt;/H1&gt;</description>
      <pubDate>Thu, 24 May 2018 17:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417956#M169210</guid>
      <dc:creator>vipmakka</dc:creator>
      <dc:date>2018-05-24T17:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417957#M169211</link>
      <description>&lt;P&gt;Interesting fields are key-value pairs that Splunk extracts when searching the data. When you dispatch a search, Splunk will try to identify delimiters such as an equal sign or colon and assign the value on the left as the field and the value on the right as the value. It will then take these key-value pairs and list them under &lt;CODE&gt;interesting fields&lt;/CODE&gt; if that fields is atleast 20% of the search range by default. You can pop open the fields at the bottom of the selection and select any fields that you want at the top and they become &lt;CODE&gt;selected fields&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/7.0.3/Knowledge/Aboutfields"&gt;http://docs.splunk.com/Documentation/SplunkCloud/7.0.3/Knowledge/Aboutfields&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 18:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417957#M169211</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-05-24T18:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417958#M169212</link>
      <description>&lt;P&gt;Thank you  skoelpin!&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 18:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417958#M169212</guid>
      <dc:creator>vipmakka</dc:creator>
      <dc:date>2018-05-24T18:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417959#M169213</link>
      <description>&lt;P&gt;In addition, @DalJeanis commented at &lt;A href="https://answers.splunk.com/answers/560735/why-sometimes-sourcetype-doesnt-appear-under-selec.html"&gt;Why sometimes sourcetype doesn't appear under Selected Fields?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;-- An interesting field is any field that appears in 20% or more of the data, but is not a selected field. (You can change the 20% number if you want.)&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 18:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417959#M169213</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-05-24T18:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417960#M169214</link>
      <description>&lt;P&gt;@vipmakka, go through &lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html"&gt;Splunk Fundamentals 1&lt;/A&gt; free course where module 3 talks about this in details. &lt;/P&gt;

&lt;P&gt;Once you complete the self paced e-learning course you are eligible to take an exam and become Splunk Certified User as well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 18:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417960#M169214</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-05-24T18:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417961#M169215</link>
      <description>&lt;P&gt;@ddrillic "You can change the 20% number if you want." Where? Which .conf file or Splunk Web page?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 21:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417961#M169215</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2019-06-10T21:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417962#M169216</link>
      <description>&lt;P&gt;Hi @DUThibault  , did you get any scope on where we can change this Interesting field filtering percentage?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 03:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/417962#M169216</guid>
      <dc:creator>bishtk</dc:creator>
      <dc:date>2019-10-10T03:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: What is an interesting field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/558241#M169217</link>
      <description>&lt;P&gt;where are these extractions defined? I do not see anything under props.conf on search head which comes with default Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;EXTRACT-&amp;lt;class&amp;gt; = [&amp;lt;regex&amp;gt;|&amp;lt;regex&amp;gt; in &amp;lt;src_field&amp;gt;]&lt;/PRE&gt;&lt;P&gt;For example: if I search for&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=_internal sourcetype=splunkd, I see a range of fields in "interesting fields".&lt;/P&gt;&lt;P&gt;Where in props.conf is the corresponding EXTRACT-&amp;lt;class&amp;gt; defined for it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume: Selected fields= index time fields.&lt;/P&gt;&lt;P&gt;Interesting fields=search time extracted fields&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-an-interesting-field/m-p/558241#M169217</guid>
      <dc:creator>goelt2000</dc:creator>
      <dc:date>2021-07-04T05:22:01Z</dc:date>
    </item>
  </channel>
</rss>

