What are the default time and results limits for a subsearch?
When Splunk encounters repeating JSON data structures in an event, they are extracted as multivalue fields. These allow multiple values to be stored under a single field, which is common with arrays in JSON data.
Carmelina
7 days agoHildegarde
11 days agoRemedios
12 days agoFlo
16 days agoSvetlana
18 days agoBrock
21 days agoEmilio
23 days agoRupert
24 days ago