Splunk Search

Field Extraction Default Delimiter

khodges_splunk
Splunk Employee
Splunk Employee

I know that Splunk will automatically extract fields for field=xyz patterns in my data. How can I tell Splunk to also automatically extract for field:pattern in my data?

Tags (2)
0 Karma

stefandagerman
Path Finder

If there is no space after the ':', automatic field extraction will not happen and you will instead need to setup the required field extractions as per http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/Addfieldsatsearchtime

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!