- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the role of INDEXED_VALUE in fields.conf

brandy81
Path Finder
03-10-2021
11:04 PM
Hi,
There is the description for INDEXED_VALUE in fields.conf
INDEXED_VALUE = [true|false|<sed-cmd>|<simple-substitution-string>] * Set this to true if the value is in the raw text of the event. * Set this to false if the value is not in the raw text of the event. * Setting this to true expands any search for key=value into a search of value AND key=value (since value is indexed).
* NOTE: You only need to set indexed_value if indexed = false.
INDEXED_VALUE is used when indexed = false according to the description. Then, when is the option INDEXED_VALUE used? Which circumstances require this option?
Is there a case where only value is indexed and key(field) is not indexed?
The description makes me confused.. Hope anyone help me out.
Thanks a lot.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
03-11-2021
12:25 AM
Hi
Maybe these answers, blogs and docs helps to understand this?
- https://www.splunk.com/en_us/blog/tips-and-tricks/cannot-search-based-on-an-extracted-field.html
- https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/Exampleconfigurationswithprops.conf
- https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-inconsistent-event-counts-when-using-...
r. Ismo
