Field extractions allow you to parse fields from your log messages at the time the messages are ingested, which eliminates the need to parse fields at the query level. With Field Extraction Rules (FERs) in place, users can use the pre-parsed fields for ad-hoc searches, scheduled searches, real-time alerts, and dashboards. In addition, field extraction rules help standardize field names and searches, simplify the search syntax and scope definition, and improve search performance.
Note that fields are extracted from the time you create your FER moving forward. Therefore, set your FERs early on to take advantage of this automatic parsing mechanism.
For best practices on naming your fields, see Field Naming Convention.
The Manage Data > Settings > Field Extraction Rules page displays the following information:
- Field extraction rule's status, enabled or disabled.
- Rule Name.
- Rule Scope.
- Rule Fields.
- Created date and time by user.
- Last modified date and time by user.
On the Manage Data > Settings > Field Extraction Rules page you can: