Using the extract fields interface

Sometimes, you will want to extract specific parts of a larger field or other blob of data within an event as an individual field. You can use the field extractor wizard to create new fields from event data using two extraction methods: regular expression for unstructured event data, and delimiters for structured data where the fields in each event are separated by a common delimiter, such as a comma, space, or tab, in cases where Splunk doesn't know how to label these fields.

To get started, enter a search string and retrieve a sample of the events you want to perform a field extraction on. You can then start the field extractor wizard from four locations:

  • Click Extract New Fields at the bottom of the ...

Get Splunk 7.x Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.