Search app

noun

Splunk's default interface for searching and analyzing IT data. The Search app enables you to index data into Splunk, add knowledge, build reports, and create alerts. The Search app can be used across many areas of IT including application management, operations management, security, and compliance.

The Search app includes the main search view, called the timeline, as well as a number of useful dashboards. The default dashboards include information about Splunk's statistics (licensing, cpu usage and more) as well as the top ten sources, source types and hosts.

For more information

In the User Manual:

In the Admin Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time