field discovery

field discovery


The process by which Splunk Enterprise extracts key=value pairs from event data at search time. When field discovery is enabled, Splunk Enterprise:

  • Extracts the first 100 fields in the event data that match obvious key=value pairs.
  • Extracts any fields that you explicitly mention in the search.
  • Performs custom field extractions that you define through the Field Extractor, the Extracted Fields page, configuration files, or search commands such as rex.

You can disable field discovery to improve search performance. To disable field discovery, change your search mode to Fast.

For more information

In the Knowledge Manager Manual:

In the Search Manual: