Splunk Search

How does punct work?

cpeteman
Contributor

NOTE: I figured that a lot of people will search "How does punct work?" and want to know. So if you were wondering: Punct info about half way down is a basic explanation.

ACTUAL QUESTION:This questions is not as easy as the title sounds. I know exactly WHAT punct does my question is where does it do it? I want to make a similar field but I cannot find the punct field extraction in manager->fields. Does anyone know how to look at this?

Tags (2)
1 Solution

lguinn2
Legend

punct is called both an "internal" field and a "default" field. Like many other default fields, it is computed at parsing time and stored in the index. This is very different than search-time fields.

I agree with Luke; I think this is done in code as part of the parsing process. But perhaps a more knowledgeable person will chime in.

Documentation here: Use default fields

I couldn't find anything else.

View solution in original post

lguinn2
Legend

punct is called both an "internal" field and a "default" field. Like many other default fields, it is computed at parsing time and stored in the index. This is very different than search-time fields.

I agree with Luke; I think this is done in code as part of the parsing process. But perhaps a more knowledgeable person will chime in.

Documentation here: Use default fields

I couldn't find anything else.

cpeteman
Contributor

"didn't think that it would make sense to be a binary"
I meant that I didn't remember that it would make more sense that way. lol

0 Karma

saurabh_tek11
Communicator

@cpeteman @lukejadamec, To know more about punct you may refer to my answer here. Hope this will be of your help. Thank you - Saurabh

0 Karma

cpeteman
Contributor

Good enough for me I knew it was a default field but didn't think that it would make sense to be a binary. Coolio.

0 Karma

lukejadamec
Super Champion

Sounds like Splunk proprietary binary code to me.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...