![Implementing Splunk 7(Third Edition)](https://wfqqreader-1252317822.image.myqcloud.com/cover/64/36700064/b_36700064.jpg)
上QQ阅读APP看书,第一时间看更新
Working with fields
All the fields that we have used so far were either indexed fields (such as host, sourcetype, and _time) or fields that were automatically extracted from key=value pairs. Unfortunately, most logs don't follow this format, especially for the first few values in each event. New fields can be created either using inline commands or through configuration.