input

noun

The first segment of the data pipeline, in which Splunk acquires the raw data stream from its source, breaks it into 64K blocks, and annotates each block with some metadata keys.

Once data has been input, it moves to the next segment of the pipeline, parsing.

Data input can occur on either an indexer or a forwarder.

For more information

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time