internal field

A default field that contains general information about the events Splunk indexed. Internal fields are indicated by a leading underscore in their field name, for example: _raw is an internal field that contains the original raw data of the event, while the value of _time is the event's timestamp expressed in Unix time.

For more information

In the User manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time