Knowledge Manager Manual

 


Overview of field extraction

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Overview of field extraction

When Splunk indexes event data, it extracts by default a set of fields that are common to most events, and which are commonly used in Splunk searches and reports. These default fields include:

For a full listing of the default fields that Splunk identifies during the indexing process, and examples of how they can be used in a search, see "Use default and internal fields" in the User manual.


Extract additional fields

Splunk enables you to extract additional fields when you determine that the default fields it identifies at index time and the fields it extracts automatically at search time aren't enough. As a Splunk knowledge manager, you can create sets of these custom extracted fields to track event information that is unique and important to your organization's needs. For more information, see the topics in the "Work with fields" chapter of this manual. There, you'll learn how to:

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!