What are the default time and results limits for a subsearch?
When Splunk encounters repeating JSON data structures in an event, they are extracted as multivalue fields. These allow multiple values to be stored under a single field, which is common with arrays in JSON data.
Brock
1 days agoEmilio
3 days agoRupert
4 days ago