Configure indexed field extraction
Configure indexed field extraction
There are three types of fields that Splunk can extract at index time:
- Default fields
- Custom fields
- File header fields
Splunk always extracts a set of default fields for each event. You can configure it to also extract custom and, for some data, file header fields.
For more information on indexed field extraction, see the chapter "Configure indexed field extraction" in this manual.
This documentation applies to the following versions of Splunk: 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 , 4.3.3 , 4.3.4 , 4.3.5 , 4.3.6 , 5.0 , 5.0.1 , 5.0.2 View the Article History for its revisions.