punct

noun

A field, the value of which is the pattern of the first 30 punctuation characters in the first line of the event with which it is associated. In other words, punct shows you what an event would look like if all of the letters, numbers, and spaces within it were removed, leaving only characters such as periods, colons, parentheses, quotes, question marks, dashes, and underscores.

For example, this event:

172.26.34.223 - - [01/Jul/2005:12:05:27 -0700] "GET /trade/app?action=logout HTTP/1.1" 200 2953

Produces this punct value:

..._-_-_[:::_-]_\"_?=_/.\"__

punct is a default field that Splunk extracts for each event it indexes. As such you can use it as a tool for searching on and identifying groups of events that have the same punctuation structure.

For more information

In the User Manual:

In the Knowledge Manager Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time