Getting Data In

If I have no transforms.conf or props.conf, when are fieldnames + fieldvalues extracted?


So if I had incoming data and it goes to an indexer, would the fieldnames/fieldvalues be extracted at that point as they are being indexed or are fieldnames/fieldvalues extracted during search time?

transforms.conf/props.conf would make it so that the fieldnames/fieldvalues are extracted during indexing, correct?

0 Karma


Fields are extracted at search time unless Splunk is explicitly told to do so at index time. Since you didn't say to, nothing is extracted at index time.

If this reply helps you, an upvote would be appreciated.
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!