event

noun

A single piece of data in Splunk, similar to a record in a log file or other data input. When Splunk eats data, it breaks the data up into individual pieces and gives each piece a timestamp, host, source, and source type. Often, a single event corresponds nicely to a single line in your inputs, but some inputs have multiline events (for example, XML logs) and some inputs actually have multiple events on a single line. When you run a search, events are what you get back.

For more information

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time