Sometimes, you will want to extract specific parts of a larger field or other blob of data within an event as an individual field. You can use the field extractor wizard to create new fields from event data using two extraction methods: regular expression for unstructured event data, and delimiters for structured data where the fields in each event are separated by a common delimiter, such as a comma, space, or tab, in cases where Splunk doesn't know how to label these fields.
To get started, enter a search string and retrieve a sample of the events you want to perform a field extraction on. You can then start the field extractor wizard from four locations:
- Click Extract New Fields at the bottom of the ...