
Overview
This three-hour course is for knowledge managers who want to learn about field extraction and the Field Extractor (FX) utility. Topics will cover when certain fields are extracted and how to use the FX to create regex and delimited field extractions.
 Limited time offer: Splunk Core Certified Power User certification at 30% discount!
Skills Covered
Please refer to course overview.
Prerequisites
To be successful, students should have a solid understanding of the following:
- How Splunk works
- Knowledge Objects
Target Audience
Search Experts Knowledge Managers.

Module 1: Using the Field Extractor
- Explore the different types of extracted fields and when they are extracted
- Define the Splunk Web Field Extractor (FX)
Module 2: Creating Regex Field Extractions
- Identify basics of regular expressions (regex)
- Explore the regex field extraction workflow
- Edit regex for field extractions
Module 3: Creating Delimited Field Extractions
- Â Identify delimited field values in event data
- Explore the delimited field extraction workflow
- Explain the use of forwarder management
- Configure forwarders to be deployment clients
- Managing forwarders using deployment apps
Dates & Locations
July 29, 2026 - July 29, 2026
September 23, 2026 - September 23, 2026

Exam & Certification
This course is not associated with any Certification.
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631























