Which field is required for an event annotation?
The _time field is required for event annotations in Splunk. This field specifies the time point or range where the annotation should be applied, helping correlate annotations with the correct temporal data.
Eloisa
16 days agoHubert
23 hours agoArminda
21 days ago