What are the default time and results limits for a subsearch?
When Splunk encounters repeating JSON data structures in an event, they are extracted as multivalue fields. These allow multiple values to be stored under a single field, which is common with arrays in JSON data.
Hildegarde
2 days agoRemedios
3 days agoFlo
7 days agoSvetlana
9 days agoBrock
12 days agoEmilio
14 days agoRupert
15 days ago