source

noun

A default field that identifies the source of the event. In the case of data monitored from files and directories, source consists of the full pathname of the file or directory. In the case of a network-based source, the source field consists of the protocol and port, such as UDP:514.

Each event has a source field. The indexer generates the source field at index time. The source field is widely used in searches.

For more information

In the User Manual:

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time