search field

A field that is extracted by Splunk at search time, or which Splunk extracts at search time with the help of custom field extraction configurations, the Interactive Field Extractor (IFX), or search commands like rex.

Fields that are extracted by Splunk during during event data processing and indexing are referred to as default fields or indexed fields.

For more information

In the Knowledge Manager Manual:

In the Mangaging Indexers and Clusters Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time