field extraction
noun
Refers both to the process by which fields are extracted from event data, and the results of that process, also referred to as extracted fields. Field extraction can take place either before events are indexed (in the case of default and indexed fields) or after event indexing (in the case of search fields).
Field extractions are a type of knowledge object.
Splunk automatically extracts a set of default fields for each event it indexes. You can "create" more "custom" fields by defining additional index-time and search-time field extractions. You can accomplish this manual field extraction through the use of search commands, the Interactive Field Extractor, and configuration files.
Related terms
For more information
In the User Manual:
- Extract and add new fields
- Extract fields with search commands
- Extract fields interactively in Splunk Web
In the Knowledge Manager Manual:
In the Getting Data In Manual: