Using Fields

Learn the role of fields in searches, field discovery, using fields in searches, and the difference between persistent and temporary fields.

This 3-hour course is for power users who want to learn about fields and how to use fields in searches. Learn how fields can refine your search results, discover available fields, and effectively utilize them in your queries. Understand the difference between persistent and temporary fields and explore how to leverage external data sources to enrich your search outcomes.

Course Topics

  • What are Fields?
     ,
  • What is Field Discovery?
     ,
  • Using Fields in Searches
     ,
  • Comparing Temporary versus Persistent Fields
     ,
  • Enriching Data

Prerequisite Knowledge

To be successful, students should have a solid understanding of the following:

  • How Splunk works
    .
  • Creating search queries
    .
  • Knowledge objects

Course Format

  • Instructor-led or eLearning

Course Objective

Topic 1

What are Fields?

  • Understand fields and field auto-extraction
  • Explore the Fields sidebar
  • Add fields to the Selected Fields list
  • Explore and generate reports from the Fields window

Topic 2

What is Field Discovery?

  • Understand Field Discovery
  • Explore search modes and their effect on search results

Topic 3

Using Fields in Searches

  • Use fields correctly in basic searches
  • Use fields with operators
  • Use the rename command
  • Use the fields command to improve search performance

Topic 4

Comparing Temporary versus Persistent Fields

  • Differentiate between temporary and persistent fields
  • Create temporary fields with the eval command
  • Extract temporary fields with the erex and rex commands

Topic 5

Enriching Data

  • Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data

Limited Spots Available, Sign up today!