The process by which Splunk Enterprise extracts
key=value pairs from event data at search time. When field discovery is enabled, Splunk Enterprise:
- Extracts the first 100 fields in the event data that match obvious
- Extracts any fields that you explicitly mention in the search.
- Performs custom field extractions that you define through the Field Extractor, the Extracted Fields page, configuration files, or search commands such as
You can disable field discovery to improve search performance. To disable field discovery, change your search mode to Fast.
For more information
In the Knowledge Manager Manual:
In the Search Manual: