<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract fields in query or in config file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672435#M230325</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you extract a field using the rex command you have this extraction only in the search,&lt;/P&gt;&lt;P&gt;if you have a field extraction (even if done with athe same regex) in conf file (that means save the regex as field extraction), you can use the field extractions in all searches (related to the permission of the knowledge object).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 20 Dec 2023 17:34:50 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-12-20T17:34:50Z</dc:date>
    <item>
      <title>Extract fields in query or in config file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672433#M230324</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;What is the different between Extract fields in query with rex or in config file.&lt;/P&gt;&lt;P&gt;Pros and cons?&lt;/P&gt;&lt;P&gt;how about performance?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 16:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672433#M230324</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-12-20T16:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields in query or in config file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672435#M230325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you extract a field using the rex command you have this extraction only in the search,&lt;/P&gt;&lt;P&gt;if you have a field extraction (even if done with athe same regex) in conf file (that means save the regex as field extraction), you can use the field extractions in all searches (related to the permission of the knowledge object).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 17:34:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672435#M230325</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-20T17:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields in query or in config file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672436#M230326</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;How about performance?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 17:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672436#M230326</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-12-20T17:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields in query or in config file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672439#M230328</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;exctly the same because the field exraction is performed at search time.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 17:40:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672439#M230328</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-20T17:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields in query or in config file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672449#M230333</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it’s probably same, but (at least in there) if you have lot of those in conf files then those could minimally slow down the execution time as those conf files load every time when you are executed a query. But unless you haven’t thousands of those it probably don’t mark anything.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-in-query-or-in-config-file/m-p/672449#M230333</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-12-20T19:48:36Z</dc:date>
    </item>
  </channel>
</rss>

