<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Websites that describes about Interesting Fields? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455463#M191271</link>
    <description>&lt;P&gt;There can be no such Splunk document.  Field names and their contents vary wildly depending on the source of the data.  To find out what a 'RecordNumber' or a 'package' is you would have to consult the documentation of the product that produced those fields.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2019 15:02:16 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-08-16T15:02:16Z</dc:date>
    <item>
      <title>Websites that describes about Interesting Fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455461#M191269</link>
      <description>&lt;P&gt;Is there a website on Splunk docs that describe about interesting fields and what each field is about? I did research on trying to find what these field names are but still I do not know what they do. Some of the interesting fields I do not understand are RecordNumber and package.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 14:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455461#M191269</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-16T14:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Websites that describes about Interesting Fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455462#M191270</link>
      <description>&lt;P&gt;Interesting fields, are just the other fields extracted from the events. &lt;/P&gt;

&lt;P&gt;Information on the fields extracted from an event, if available, would be found in the documentation of the add-on used to extract the fields. &lt;/P&gt;

&lt;P&gt;You may need to go back to the  documentation of the application/appliance/etc producing the events. &lt;/P&gt;

&lt;P&gt;NOTE:  Some sourcetype, like weblogs that contain text that gets recognized as  key=value pairs.  For example a CGI web request :&lt;/P&gt;

&lt;P&gt;/en-US/app/search/search?&lt;STRONG&gt;display.general.type=statistics&lt;/STRONG&gt;&amp;amp;&lt;STRONG&gt;display.page.search.tab=statistics&lt;/STRONG&gt;&amp;amp;&lt;STRONG&gt;display.page.search.mode=fast&lt;/STRONG&gt;&amp;amp;dispatch.sample_ratio=1&lt;/P&gt;

&lt;P&gt;Splunk by default will extract these key=value pairs, and if enough events contain them, they would show up under interesting fields. Despite the fact that the fields are not actually valid fields for that event. &lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455462#M191270</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2019-08-16T15:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Websites that describes about Interesting Fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455463#M191271</link>
      <description>&lt;P&gt;There can be no such Splunk document.  Field names and their contents vary wildly depending on the source of the data.  To find out what a 'RecordNumber' or a 'package' is you would have to consult the documentation of the product that produced those fields.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455463#M191271</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-16T15:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Websites that describes about Interesting Fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455464#M191272</link>
      <description>&lt;P&gt;Basically just look at where the information form that product is coming from in order to make sense of what that field name is about. Sometimes with the documentation I see these fields being used like the other people know what that person means and question how they do know what there purpose of their function.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:12:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455464#M191272</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-16T15:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Websites that describes about Interesting Fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455465#M191273</link>
      <description>&lt;P&gt;Basically, yes.  Product documentation is often written for people already familiar with the product (not so much with Spunk) so it helps to find a person with experience using that product to help you make sense of the data.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455465#M191273</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-16T15:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Websites that describes about Interesting Fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455466#M191274</link>
      <description>&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Websites-that-describes-about-Interesting-Fields/m-p/455466#M191274</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-16T15:50:06Z</dc:date>
    </item>
  </channel>
</rss>

