Splunk Search Commands

FIELDS

In Splunk, the "fields" command is used to extract and manipulate specific fields within the data being searched. This command can be used to extract fields that are already present in the data, as well as to create new fields based on the values of existing fields.

Add fields

Use these commands to add new fields.

Fields 1

Extract fields

These commands provide different ways to extract new fields from search results.

fields 2

Modify fields and field values

Use these commands to modify fields or their values.

Fields 3