There are two phases of field extraction: **Index-Time** (when data is ingested) and **Search-Time** (when you run a query).
Index-time extractions are stored permanently in the TSIDX files and are faster to query, but they are rigid and consume more disk space.
Search-time extractions are flexible (using `rex`, `eval`) but slower because they parse raw data on every search.