Creating Field Extractions (CFE)

 

Contenu

This three-hour module is for knowledge managers who want to learn about field extraction and the Field Extractor (FX) utility. Topics will cover when certain fields are extracted and how to use the FX to create regex and delimited field extractions.

Pré-requis

To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Knowledge objects

Objectifs

  • Using the Field Extractor
  • Creating Regex Field Extractions
  • Creating Delimited Field Extractions

Outline: Creating Field Extractions (CFE)

Topic 1 - Using the Field Extractor

  • Understand types of extracted fields and when they are extracted
  • Explore the Splunk Web Field Extractor (FX)

Topic 2 - Creating Regex Field Extractions

  • Identify basics of regular expressions (regex)
  • Understand the regex field extraction workflow
  • Edit regex for field extractions

Topic 3 - Creating Delimited Field Extractions

  • Identify delimited field values in event data
  • Understand the delimited field extraction workflow

Prix & Delivery methods

Formation en ligne

Durée 0,5 jours

Prix
  • Online Training: CAD 635,–
  • Online Training: US$ 500,–
Formation en salle équipée

Durée 0,5 jours

Prix
  • Canada: CAD 635,–

Cliquez sur le nom de la ville ou sur "Formation en ligne" pour réserver Agenda

This is an Instructor-Led Classroom course
Instructor-led Online Training:   Cours en ligne avec instructeur
*   This class is delivered by a partner.

Etats-Unis

Formation en ligne 14:00 US/Eastern Cette formation est réalisée par un partenaire S'inscrire
Formation en ligne 14:00 US/Eastern Cette formation est réalisée par un partenaire S'inscrire