
Data model objects also include attributes, which are simply fields (exposed for use in reporting) associated with the dataset that the object represents. There are five types of object attributes: auto-extracted (fields that Splunk derives at search time), eval expressions (field derived from an eval expression that you enter in the attribute definition), lookups (they add fields from external data sources such as CSV files and scripts), regular expressions (a field that is extracted from the object event data using a regular expression) and GeoIP (of a lookup that adds geographical attributes, such as latitude, longitude, country, and city to events in the object dataset).

Attributes fall into one of three categories: inherited ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.