At index time, in which field does Splunk store the timestamp value?
At index time, in which field does Splunk store the timestamp value?
Splunk stores the timestamp value in the '_time' field at index time. This field is a standardized field used by Splunk to record the time when an event occurs, which can then be used for time-based searches and analyses.
is ok b
B, page 199