indexer

noun

The Splunk instance that indexes data, transforming raw data into events and placing the results into an index.

The indexer frequently, but not always, also performs the other key Splunk functions: data input and searches. In larger deployments, forwarders handle the input of data, which they then send on to the indexer for indexing. Similarly, searches can also be performed by separate Splunk instances, called search heads.

For more information

In the Installation manual:

In the Admin manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time