Splunk Search

Performance of EXTRACT- vs REPORT- for same regex

Jason
Motivator

Is there any difference in performance when using

props.conf
EXTRACT-name1 = long (?<field1>regex) with lots of (?<field2>capture groups)

versus

props.conf
REPORT-name2 = transform_name

transforms.conf
[transform_name]
REGEX = long (regex) with lots of (capture groups)
FORMAT = field1::$1 field2::$2

?

Tags (2)
1 Solution

araitz
Splunk Employee
Splunk Employee

Since they are both extracted by the same regex processor at search time, my educated guess would be no.

Due to tradition, style, and readability, I personally tend to use the transforms.conf specification.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Since they are both extracted by the same regex processor at search time, my educated guess would be no.

Due to tradition, style, and readability, I personally tend to use the transforms.conf specification.

Jason
Motivator

REPORT also allows you to apply the same regex easily to multiple data types without having multiple copies of the regex around - another reason why I use it.

Jason
Motivator

Thanks - so do I. But I was working up a regex on the search bar with rex yesterday and tossed it right in an EXTRACT - so I was wondering.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...