The time span from when Splunk Enterprise receives new data to when the data is written to a Splunk Enterprise index. During that time, the data is parsed into segments and events; default fields and timestamps are extracted; and transforms are applied.
For more information
In Managing Indexers and Clusters of Indexers:
In Getting Data In: