Extracts field-value pairs from the search results.


extract [<extract-options>... ] [<extractor-name>...]

Required arguments


Optional arguments

Syntax: clean_keys=<bool> | kvdelim=<string> | limit=<int> | maxchars=<int> | mv_add=<bool> | pairdelim=<string> | reload=<bool> | segment=<bool>
Description: Options for defining the extraction. See the ""Extract_options" section in this topic.
Syntax: <string>
Description: A stanza in the transforms.conf file. This is used when the props.conf file does not explicitly cause an extraction for this source, sourcetype, or host.

Extract options

Syntax: clean_keys=<bool>
Description: Specifies whether to clean keys. Overrides CLEAN_KEYS in the transforms.conf file.
Default: The value specified in the CLEAN_KEYS in the transforms.conf file.
Syntax: kvdelim=<string>
Description: A list of character delimiters that separate the key from the value.
Syntax: limit=<int>
Description: Specifies how many automatic key-value pairs to extract.
Default: 50
Syntax: maxchars=<int>
Description: Specifies how many characters to look into the event.
Default: 10240
Syntax: mv_add=<bool>
Description: Specifies whether to create multivalued fields. Overrides the value for the MV_ADD parameter in the transforms.conf file.
Default: false
Syntax: pair=<string>
Description: A list of character delimiters that separate the key-value pairs from each other.
Syntax: reload=<bool>
Description: Specifies whether to force reloading of the props.conf and transforms.conf files.
Default: false
Syntax: segment=<bool>
Description: Specifies whether to note the locations of the key-value pairs with the results.
Default: false



The alias for the extract command is kv.


Example 1:

Extract field-value pairs that are delimited by the pipe or semicolon characters ( |; ). Extract values of the fields that are delimited by the equal or colon characters ( =: ). The delimiters are individual characters. In this example the "=" or ":" character is used to delimit the key value. Similarly, a "|" or ";" is used to delimit the field-value pair itself.

... | extract pairdelim="|;", kvdelim="=:"

Example 2:

Extract field-value pairs and reload field extraction settings from disk.

... | extract reload=true

Example 3:

Extract field-value pairs that are defined in the stanza 'access-extractions' in the transforms.conf file.

... | extract access-extractions

See also

kvform, multikv, rex, xmlkv,


Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the extract command.


This documentation applies to the following versions of Splunk Cloud: 6.5.0, 6.5.1, 6.5.1612, 6.6.0, 6.6.1, 6.6.3

