host

noun

A default field that contains the hostname or IP address of the network device that generated an event. Each event has a host field. The indexer generates the host field at index time. The host field is widely used in searches, as a way to narrow the search results to events originating from a specific device.

There are ways to configure host values for events when events are input into Splunk. You can set a default host for a Splunk server, file, or directory input. You can also arrange to have Splunk assign host values to events based on data in those events.

For more information

In the Knowledge Manager Manual:

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time