Which field is required for an event annotation?
The _time field is required for event annotations in Splunk. This field specifies the time point or range where the annotation should be applied, helping correlate annotations with the correct temporal data.
Luis
3 days agoArminda
7 days agoKing
13 days agoBok
14 days agoFelix
14 days agoEloisa
1 months agoVeronica
12 days agoHubert
16 days agoArminda
1 months ago