real-time search

noun or verb

A search that displays a live and continuous view of events as they stream into Splunk, prior to being indexed. You can design reports that display real-time results, and you can set up custom dashboards that utilize real-time searches.

Time bounds for real-time searches are constantly updating (as opposed to being set when the search runs, as is the norm for historical searches). You can specify a time range that represents a sliding window of data, such as "data that has been received over the past 30 seconds." Splunk uses this window to accumulate data, so you won't see any data for such a search until 30 seconds have passed.

Real-time search can be disabled for an indexer, and you can set up permissions that map the ability to use real-time search to specific users or roles.

For more information

In the User Manual:

In the Developer Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time