Answer Posted / Mudit Kumar Saxena
By default, every event in Splunk has a set of predefined fields such as _time (timestamp), host (source machine), sourcetype (type of data), and index (index where the data is stored). These are called internal or default fields.
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers