Which Field/Value pair will return only events found in the index named security?
Splunk extracts fields from event data at index time and at search time.
Splunk internal fields contains general information about events and starts from underscore i.e. _ .