Splunk Search

Ingestion Method as Field?

morethanyell
Builder

Hi. I've noticed there are some hidden fields in every event ingested into Splunk, like _indextime. Is there some sort of hidden field where it tells the method of ingestion, such as _indexingmethod = TCP | FileMonitor | HEC | etc

Thanks in advance.

0 Karma
1 Solution

jawaharas
Motivator

I don't think there are any. The list of default fields can be referred here-

https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Aboutdefaultfields

View solution in original post

jawaharas
Motivator

I don't think there are any. The list of default fields can be referred here-

https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Aboutdefaultfields

morethanyell
Builder

I hope they include it in future version.

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...