Getting Data In

What is the purpose of the _s _st and _h indexed fields?

Super Champion

Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourcetype and host, but I'm not sure exactly how or why these were added in Splunk 4.x.

Tags (2)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

those are ids for source, sourcetype and host - they can be used for index regeneration purposes

View solution in original post

Splunk Employee
Splunk Employee

those are ids for source, sourcetype and host - they can be used for index regeneration purposes

View solution in original post

Splunk Employee
Splunk Employee

what is index regeneration? is that when you un-archive?

0 Karma