The repository for data in Splunk Enterprise. When Splunk Enterprise indexes raw event data, it transforms the data into searchable events. Indexes reside in flat files on the Splunk Enterprise instance known as the indexer.


In general, the act of processing raw data and adding the processed data to an index.

Specifically, indexing is the third segment of the data pipeline, in which Splunk Enterprise takes parsed events and writes them to the search index on disk.

For more information

In Managing Indexers and Clusters of Indexers:

In the Distributed Deployment Manual: