field extraction

noun

Refers both to the process by which fields are extracted from event data, and the results of that process, also referred to as extracted fields. Field extraction can take place either before events are indexed (in the case of default and indexed fields) or after event indexing (in the case of search fields).

Field extractions are a type of knowledge object.

Splunk automatically extracts a set of default fields for each event it indexes. You can "create" more "custom" fields by defining additional index-time and search-time field extractions. You can accomplish this manual field extraction through the use of search commands, the Interactive Field Extractor, and configuration files.

Related terms

For more information

In the User Manual:

In the Knowledge Manager Manual:

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time