The first segment of the data pipeline, in which Splunk Enterprise acquires the raw data stream from its source, breaks it into 64K blocks, and annotates each block with metadata keys.

After data has been acquired and split into blocks, it moves to the next segment of the pipeline, parsing.

Data input can occur on either an indexer or a forwarder.

