Splunk® Enterprise

Knowledge Manager Manual

Download manual as PDF

Download topic as PDF

Configure custom fields at search time

Use configuration files to configure custom fields at search time, to enrich your events with fields that are not discovered by available Splunk Web extraction methods. You can use .conf files such as transforms.conf and props.conf to add, maintain, and review libraries of custom field additions.

You can set up and manage search-time field extractions via Splunk Web. You cannot configure automatic key-value field extractions through Splunk Web. For more information on setting up field extractions through Splunk Web, see manage search-time field extractions.

You can locate props.conf and transforms.conf in $SPLUNK_HOME/etc/system/local/, or your own custom app directory in $SPLUNK_HOME/etc/apps/.

In general, you should try to extract your fields at search time rather than at index-time. There are relatively few cases where index-time extractions are better, and they can cause an increase in index size making your searches slower. See Configuring index-time field extractions.

Field extraction configurations must include a regular expression that specifies how to find the field that you want to extract.

See About fields.

Types of field extraction

There are three field extraction types: inline, transform, and automatic key-value.

Field extraction type Configuration location See
Inline extractions Inline extractions have EXTRACT-<class> configurations in props.conf stanzas. Configure inline extractions
Transform extractions Transform extractions have REPORT-<class> name configurations that are defined in props.conf stanzas. Their props.conf configurations must reference field transform stanzas in transforms.conf. Configure advanced extractions with field transforms
Automatic key-value extractions Automatic key-value extractions are configured in props.conf stanzas where KV_MODE is set to a valid value other than none. Configure automatic key-value field extraction

When to use inline or transform extractions

Field extraction type Situation See
Inline extractions
  • You have one regular expression per field extraction configuration.
  • You have a simple setup with one regular expression, and you want to extract multiple fields.
  • You want to create a new field by configuring an extraction.
Configure inline extractions with props.conf
Transform extractions
  • To reuse the same field-extracting regular expression across multiple sources, source types, or hosts.
  • To apply more than one field-extracting regular expression to the same source, source type, or host.
  • To set up delimiter-based field extractions.
  • To configure extractions for multivalue fields.
  • To extract fields with names that begin with numbers or underscores.
  • To extract fields from the values of another field.
  • To manage the formatting of extracted fields, in cases where you are extracting multiple fields or are extracting both the field name and field value.
Configure advanced extractions with field transforms

Both of these configurations can be set up in the regular expression as well.

Use the Field transformations page
Configure inline extractions

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters