data input

noun

A source of incoming event data being fed into Splunk. Data inputs can be live files or directories of files being written to by applications, data coming in over network ports (such as syslog), Windows event logs, registries, and WMI data, Active Directory events, or data coming from your own custom scripts.

Data inputs can also be defined on agents, or forwarders that then send the data to a central indexer.

For more information

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time