index time

noun

Time span from when Splunk becomes aware of new data to when it is actually written into a Splunk index. In between, many exciting things happen to the data as it is parsed into segments and events, default fields and timestamps are extracted, and transforms are applied. You can configure index time processing through Splunk Manager and can be set via configuration files.

For more information

In the Admin manual:

In the Getting Data In manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time