Close

Extract fields

#message#

Sample Event

This is the event from which you choose to extract fields

#sampleEvent#

Example Value(s)

Enter the value from your sample event that you want Splunk to extract. You can enter additional values for the same field on separate lines.


Rules

Restrict to:

Generated rules

#ruleset#

Preview extractions

#extractions#

Preview

Here are some of the other events that share the search as the sample event. Validate the correctness of the values Splunk has extracted for your custom field.

Provide an example value to get started.

#events#
 

Save Field Definition