multivalue field

noun

A field that has more than one value. Fields usually have a single value, but for events such as email logs, you'll often find multivalue fields in the "To:" and "Cc:" information.

You can use Splunk's search language to separate multivalue fields into single value fields, or combine single values into one field.

For more information

In the Knowledge Manager Manual:

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time