event processing

noun

Everything that happens to your data between the time you point Splunk at an input and the time the data first shows up in the Splunk index. Splunk does a lot to organize and and structure your data at index time, including handling multiline events, extracting important fields like the timestamp, and compressing the data. A lot of this is configurable and customizable via the configuration files. After your events have been processed, you can still add information like fields, tags, and event types to your events.

Splunk Web's data preview tool enables you to configure how your event data is formatted during event processing before you begin processing it in full. Use it to see how your processed events will look and make adjustments to improve their appearance.

For more information

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time