indexed field

noun

A field that is incorporated in the Splunk index at index time. Indexed fields include all of Splunk's default fields, such as host, source, and sourcetype, as well as custom index-time field extractions. In some very rare and specific cases, there is some value to adding additional fields to the index. However, this can negatively affect indexing performance and search times across your entire, and there is no way to modify or remove the field extraction afterwards. You can add plenty of non-indexed fields; these are extracted at search time.

For more information

In the Admin Manual:

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time