index

noun and verb

A repository for Splunk data. When Splunk indexes raw event data, it transforms the data into searchable events. Indexes reside in flat files on the Splunk instance known as the indexer.

As a verb, this also refers to the collective act of processing raw data and adding the processed data to an index.

More specifically, indexing is the third segment of the data pipeline, in which Splunk takes parsed events and writes them to the search index on disk.

For more information

In the Managing Indexers and Clusters manual:

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time