event data

noun

A fancy term for all the IT data that has been added to Splunk's index(es). The individual atomic units of data are called events. Splunk also stores information related to Splunk's structure and processing; all that stuff is not event data.

Related terms

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time