-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Advanced Splunk
By :

In Splunk, for any kind of analytics and visualizations, fields play a very important role. Splunk automatically tries to extract and make them available for use for known and properly configured data sources. Since there are a wide variety of sources for data, there could be many fields which do not get automatically extracted. Splunk also provides the Splunk command rex
, which can be used to extract the fields, but this command requires a good understanding of regular expressions to efficiently extract fields from the data. So Splunk provides a very easy to use field extractor to extract fields using an interactive field extractor tool via the Splunk Web interface.
Let us learn to access the field extractor to extract fields from the data, which in turn can be used to create analytics and visualizations in Splunk.
The field extractor can be accessed via the following options:
Splunk Web Console | Settings | Fields | Field Extractions | Open Field...
Change the font size
Change margin width
Change background colour