Splunk Search

Performance of EXTRACT- vs REPORT- for same regex

Jason
Motivator

Is there any difference in performance when using

props.conf
EXTRACT-name1 = long (?<field1>regex) with lots of (?<field2>capture groups)

versus

props.conf
REPORT-name2 = transform_name

transforms.conf
[transform_name]
REGEX = long (regex) with lots of (capture groups)
FORMAT = field1::$1 field2::$2

?

Tags (2)
1 Solution

araitz
Splunk Employee
Splunk Employee

Since they are both extracted by the same regex processor at search time, my educated guess would be no.

Due to tradition, style, and readability, I personally tend to use the transforms.conf specification.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Since they are both extracted by the same regex processor at search time, my educated guess would be no.

Due to tradition, style, and readability, I personally tend to use the transforms.conf specification.

Jason
Motivator

REPORT also allows you to apply the same regex easily to multiple data types without having multiple copies of the regex around - another reason why I use it.

Jason
Motivator

Thanks - so do I. But I was working up a regex on the search bar with rex yesterday and tossed it right in an EXTRACT - so I was wondering.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...