calculated field

calculated field


A field that represents the output of an eval expression. Splunk search defines and adds calculated fields to events at search-time, and it processes calculated fields after it processes search-time field extractions. This means that the eval expression at the heart of the calculated field definition can use values from one or more previously extracted fields.

Splunk search evaluates each calculated field independently of other calculated fields. You cannot chain them together by using one calculated field in the eval expression for another calculated field.

For more information

In the Knowledge Manager Manual: