event processing

noun

Everything that happens to your data between the time you point Splunk at an input and the time the data first shows up in the Splunk index. Splunk does a lot to organize and and structure your data at index time, including handling multiline events, extracting important fields like the timestamp, and compressing the data. A lot of this is configurable and customizable via the configuration files. After your events have been processed, you can still add information like fields, tags, and event types to your events.

For more information

In the Getting Data In Manual

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time