Splunk Search

What is difference between report and field extraction?

jangid
Builder

What is the difference between REPORT- and FIELD-?

1 Solution

Drainy
Champion

REPORT- is a search time extraction
FIELDALIAS- creates an alias for an existing field name, so if you already had a field such as ComputerName automatically extracted from windows event logs, you could create an alias to change it to comp_name for example.

Where have you seen FIELD- ? Its not documented.

View solution in original post

Drainy
Champion

Ah, best bet is to just post a comment asking if anyone had any ideas to bump it back up the list 🙂

0 Karma

Drainy
Champion

REPORT- is a search time extraction
FIELDALIAS- creates an alias for an existing field name, so if you already had a field such as ComputerName automatically extracted from windows event logs, you could create an alias to change it to comp_name for example.

Where have you seen FIELD- ? Its not documented.

Drainy
Champion

ah, I would assume it was a typo. If it did work it is probably just short-hand for FIELDALIAS much like Splunk doesn't care if you use TRANSFORM or TRANSFORMS

0 Karma

jangid
Builder

Thanks Drainy, I don't know exactly where I saw but I am sure it was either in Splunkbase or Answers.

Anyway Now after your reply there is no meaning of my question.

Thanks Drainy

jangid
Builder

Thanks Drainy,
my question is still open and unanswered. I didn't get any answer so thought better to close it because there is no delete option.

0 Karma

Drainy
Champion

If you're happy its been answered then all you need to do is click the tick next to the answer below to accept it 🙂 If you've answered it elsewhere, post it as your own answer and then you can accept that too. We keep closing questions for spam or duplicates

0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

Are you referring to REPORT- and EXTRACT-? If so, the difference is that REPORT can reference one or more stanzas in transforms.conf while EXTRACT does not utilize transforms.conf (both are for search-time field extraction). It is explained in detail here, under the section "Field Extraction Configuration":

http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf

jangid
Builder

Thanks for your reply.
I mean REPORT- and FIELD-

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...