The default fields for each event that are returned in a search are as follows:
host, index, linecount, punct, source, sourcetype, splunk_server, timestamp
and the default selected fields are:
host, source, sourcetype
index is included as a default but not selected.
Therefore, do you have a specific output you were looking for?
... View more