Splunk Search

Field Extraction Default Delimiter

khodges_splunk
Splunk Employee
Splunk Employee

I know that Splunk will automatically extract fields for field=xyz patterns in my data. How can I tell Splunk to also automatically extract for field:pattern in my data?

Tags (2)
0 Karma

stefandagerman
Path Finder

If there is no space after the ':', automatic field extraction will not happen and you will instead need to setup the required field extractions as per http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/Addfieldsatsearchtime

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...