standard search

noun

A term used to differentiate searches that search through events within a distinct time range (such as the past hour, the previous day, or between 2 and 4 last Tuesday) from real-time searches, which run until they are stopped, and which search incoming events as they are processed for indexing. Standard searches usually review historical data, but can be set up to review events with future-dated timestamps, if your index contains them.

You can arrange to have standard searches run on a regular schedule for alerting and summary indexing purposes. Such searches are referred to as scheduled searches.

Related terms

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time