Splunk Enterprise

noun

A version of Splunk that includes enterprise-level features beyond those in Splunk Free. When you first install Splunk, you have temporary access to these features via a Splunk Enterprise trial license. These features include multiple users and roles, distributed search, forwarding to other systems in TCP/HTTP format, scheduled saved searches/alerting, and deployment server.

For more information

In the Installation Manual:

In the Admin Manual:

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time