interactive field extractor

noun

A feature in Splunk's Search app that lets you create custom fields dynamically while searching. The interactive field extractor (IFX) lets you extract one field at a time, based on a host, source, or source type value. IFX is especially useful if you are not familiar with regular expression syntax and usage, because it will generate field extraction regexes for you (and enable you to test them).

For more information

In the Knowledge Manager Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time