field

noun

Searchable name/value pair in Splunk event data. Fields give you more precision in searches. Splunk automatically extracts certain default fields, such as host and source type. You can also set up Splunk to create search time or index time field extractions, for example, using the Interactive Field Extractor or the rex command. Use tags or aliases to change the name of a field or group similar fields together. Field names are case-sensitive.

For more information

In the Knowledge Manager Manual:

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time