index time

index time

noun

The time span from when Splunk Enterprise receives new data to when the data is written to a Splunk Enterprise index. During that time, the data is parsed into segments and events; default fields and timestamps are extracted; and transforms are applied.

In the context of Splunk Observability Cloud, use index-time rules to transform your data, or a designated subset of your data, during ingestion into Splunk Observability Cloud.

For more information

In Managing Indexers and Clusters of Indexers:


In Getting Data In:

*
W