Splunk Answers-a-thon!

How to use field extractions?

yeasuh
Splunk Employee
Splunk Employee

How to use field extractions?

Labels (2)
Tags (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

There are multiple was to extract fields:
you can use the interactive field extration present in search 
you can using inline rex command in your search 
you can use props and transforms conf files

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

RobertMarks
Observer

There is also the option to use the search -> sidebar -> extract more fields -> and use the automatic field extractor, though this is most often just a jumping-off point for your final field extractions. 

0 Karma

RobertMarks
Observer

You can write a search time field extraction under splunk -> settings -> field extractions. A field extraction will apply to a sourcetype and can be either an inline regex based extraction, or use a TRANSFORM from transforms. conf. 

You can also extract fields at indextime using transforms.conf on the indexer/HF

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Announcing the General Availability of Splunk Enterprise Security 8.1!

We are pleased to announce the general availability of Splunk Enterprise Security 8.1. Splunk becomes the only ...

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...