<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26158" language="de" source="https://portal.flane.ch/swisscom/xml-course/splunk-suf" lastchanged="2026-03-02T17:32:39+01:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>Using Fields</title><productcode>SUF</productcode><vendorcode>SP</vendorcode><vendorname>Splunk</vendorname><fullproductcode>SP-SUF</fullproductcode><version>1.0</version><essentials>&lt;p&gt;To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How Splunk works&lt;/li&gt;&lt;li&gt;Creating search queries&lt;/li&gt;&lt;li&gt;Knowledge objects&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;Users/Analysts&lt;/li&gt;&lt;li&gt;Administrators&lt;/li&gt;&lt;li&gt;Engineers&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1 &amp;ndash; What are Fields?&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Define fields and field auto-extraction&lt;/li&gt;&lt;li&gt;Explore the Fields sidebar&lt;/li&gt;&lt;li&gt;Add fields to the Selected Fields list&lt;/li&gt;&lt;li&gt;Explore and generate reports from the Fields window&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;br/&gt;
&lt;strong&gt;Module 2 &amp;ndash; What is Field Discovery?&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand Field Discovery&lt;/li&gt;&lt;li&gt;Explore search modes and their effect on search results&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;br/&gt;
&lt;strong&gt;Module 3 &amp;ndash; Using Fields in Searches&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use fields correctly in basic searches&lt;/li&gt;&lt;li&gt;Use fields with operators&lt;/li&gt;&lt;li&gt;Use the rename command&lt;/li&gt;&lt;li&gt;Use the fields command to improve search performance&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;br/&gt;
&lt;strong&gt;Module 4 &amp;ndash; Comparing Temporary versus Persistent Fields&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Differentiate between temporary and persistent fields&lt;/li&gt;&lt;li&gt;Create temporary fields with the eval command&lt;/li&gt;&lt;li&gt;Extract temporary fields with the erex and rex commands&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;br/&gt;
&lt;strong&gt;Module 5 &amp;ndash; Enriching Data&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:



- How Splunk works
- Creating search queries
- Knowledge objects</essentials_plain><audience_plain>- Users/Analysts
- Administrators
- Engineers</audience_plain><outline_plain>Module 1 – What are Fields?



- Define fields and field auto-extraction
- Explore the Fields sidebar
- Add fields to the Selected Fields list
- Explore and generate reports from the Fields window



Module 2 – What is Field Discovery?



- Understand Field Discovery
- Explore search modes and their effect on search results



Module 3 – Using Fields in Searches



- Use fields correctly in basic searches
- Use fields with operators
- Use the rename command
- Use the fields command to improve search performance



Module 4 – Comparing Temporary versus Persistent Fields



- Differentiate between temporary and persistent fields
- Create temporary fields with the eval command
- Extract temporary fields with the erex and rex commands



Module 5 – Enriching Data



- Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data</outline_plain><duration unit="d" days="0">3 Stunden</duration><pricelist><price country="US" currency="USD">500.00</price><price country="IT" currency="USD">500.00</price><price country="GB" currency="GBP">420.00</price><price country="PL" currency="USD">500.00</price><price country="DE" currency="EUR">500.00</price><price country="CA" currency="CAD">690.00</price><price country="CH" currency="CHF">550.00</price></pricelist><miles><milesvalue country="CA" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="US" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="IT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="GB" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="SI" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="PL" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="DE" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="AT" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue><milesvalue country="CH" vendorcurrency="SPC" vendorcurrencyname="Splunk Training Units">50.00</milesvalue></miles></course>