splunkd

noun

Splunk indexer and searcher. splunkd is a distributed C/C++ server that accesses, processes and indexes streaming data and handles search requests. The other major Splunk server is splunkweb, which provides the user interface. splunkd can be run without splunkweb, for example on a forwarder.

For more information

In the Install Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time