real-time search
noun or verb
A search that displays a live and continuous view of events as they stream into Splunk, prior to being indexed. You can design reports that display real-time results, and you can set up custom dashboards that utilize real-time searches.
Time bounds for real-time searches are constantly updating (as opposed to being set when the search runs, as is the norm for historical searches). You can specify a time range that represents a sliding window of data, such as "data that has been received over the past 30 seconds." Splunk uses this window to accumulate data, so you won't see any data for such a search until 30 seconds have passed.
Real-time search can be disabled for an indexer, and you can set up permissions that map the ability to use real-time search to specific users or roles.
For more information
In the User Manual:
In the Developer Manual: