indexer

noun

The Splunk instance that indexes data, transforming raw data into events and placing the results into an index. It also searches the indexed data in response to search requests.

The indexer frequently, but not always, also performs the other key Splunk functions: data input and search management. In larger deployments, forwarders handle the input of data, which they then send on to the indexer for indexing. Similarly, although indexers always perform searches across their own data, the search process is sometimes managed by a separate Splunk instance, called a search head, which can coordinate searches across multiple indexers.

For more information

In the Managing Indexers and Clusters manual:

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time