- Implementing Splunk 7(Third Edition)
- James D. Miller
- 60字
- 2021-08-27 19:42:36
Working with fields
All the fields that we have used so far were either indexed fields (such as host, sourcetype, and _time) or fields that were automatically extracted from key=value pairs. Unfortunately, most logs don't follow this format, especially for the first few values in each event. New fields can be created either using inline commands or through configuration.