Hi. I've noticed there are some hidden fields in every event ingested into Splunk, like _indextime. Is there some sort of hidden field where it tells the method of ingestion, such as _indexingmethod = TCP | FileMonitor | HEC | etc
Thanks in advance.
I don't think there are any. The list of default fields can be referred here-
View solution in original post
I hope they include it in future version.