Splunk Search

Static Fields

tepus
Explorer

Hi everyone,

I'm going through the course Splunk Fundamentals 2 and I'm sorry if the question is too easy: what does it mean for a field to be 'static'? Namely, in the slide 151 of Splunk 7.X Fundamentals Part 2 (IOD).pdf, it is stated:
'Use FX to extract fields that are static...'
But I couldn't find any definition of a 'static' field in the documentation. What does it mean?

Any help is appreciated!

0 Karma
1 Solution

tepus
Explorer

Hi again,

Here is a just-received answer from an official Splunk instructor from the Splunk Fundamentals 2 course:

In the context of field extraction, "static" means that the value of the field will not change in terms of the regex created to extract that field. After the regex is created, Splunk will extract only the results of that regex - any change will result in the regex not working, and produce an error.

View solution in original post

0 Karma

tepus
Explorer

Hi again,

Here is a just-received answer from an official Splunk instructor from the Splunk Fundamentals 2 course:

In the context of field extraction, "static" means that the value of the field will not change in terms of the regex created to extract that field. After the regex is created, Splunk will extract only the results of that regex - any change will result in the regex not working, and produce an error.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tepus,
I don't know what they mean with "static", I can suppose that they would mean "stable" and available for searches, in other words, fields extracted with FX are available for others searches , instead if you extract a field using the rex command, field is useful only in that search.

ciao.
Giuseppe

0 Karma

tepus
Explorer

It makes sense to me. Thanks @gcusello !

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tepus,
if this answer solves your problem, please accept and/or upvote it for the other members of Community.
Ciao and next time.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...