Is there some documentation including the definition and description of fields in the _internal index.
For example:
- /opt/splunk/var/log/splunk/license_usage.log
field;
- h
- i
- idx
- s
- st
Kind regards,
I don't think so but in your particular case:
In general you can either guess what the fields are or simply look for existing Splunk searches and how they are used to find what you are looking.
Maybe the following links can help too:
https://answers.splunk.com/answers/194456/is-there-a-guide-or-map-to-understand-splunks-inte.html
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself
Regards,
J
I don't think so but in your particular case:
In general you can either guess what the fields are or simply look for existing Splunk searches and how they are used to find what you are looking.
Maybe the following links can help too:
https://answers.splunk.com/answers/194456/is-there-a-guide-or-map-to-understand-splunks-inte.html
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself
Regards,
J
Thanks for the reply. I guessed the same field descriptions, still it's strange that there is no elaborated documentation about these inputs.