Getting Data In

What is the purpose of the _s _st and _h indexed fields?

Lowell
Super Champion

Can someone shed light on the purpose of the _s _st and _h indexed fields? These seem to correspond to source, sourcetype and host, but I'm not sure exactly how or why these were added in Splunk 4.x.

Tags (2)
0 Karma
1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

those are ids for source, sourcetype and host - they can be used for index regeneration purposes

View solution in original post

Ledion_Bitincka
Splunk Employee
Splunk Employee

those are ids for source, sourcetype and host - they can be used for index regeneration purposes

Dan
Splunk Employee
Splunk Employee

what is index regeneration? is that when you un-archive?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...