matching event

noun

When Splunk is running a real-time search, it scans incoming events that contain index-time fields that indicate that they could be a match for the search. Splunk then matches these scanned events against the search criteria. If any of the events among the set of scanned events prove to be an actual match to the search criteria, Splunk identifies them in the UI as matching events.

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time