default field

noun

An indexed field that Splunk automatically recognizes in your event data at search time.

Three important default fields are host, source, and source type, which describe where the event originated. Other default fields include datetime fields, which provide additional searchable granularity to event timestamps. Splunk also automatically adds default fields classified as internal fields.

For more information

In the Getting Data In Manual:

In the Managing Indexers and Clusters Manual:

In the Knowledge Manager Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time