<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What's the difference between an event and a log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478012#M192802</link>
    <description>&lt;P&gt;Really you have 3 terms &lt;CODE&gt;event&lt;/CODE&gt;, &lt;CODE&gt;log&lt;/CODE&gt;, and &lt;CODE&gt;result&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;An &lt;CODE&gt;event&lt;/CODE&gt; is a thing that happened anywhere at any time.  It might be in Splunk and it might not.  A &lt;CODE&gt;log&lt;/CODE&gt; is the &lt;CODE&gt;digital exhaust&lt;/CODE&gt; of that event; it is the plain-text vestige that indicates than an event happened.  A &lt;CODE&gt;result&lt;/CODE&gt; is each &lt;CODE&gt;thing&lt;/CODE&gt; that is returned from a Splunk search.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2019 14:27:49 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-09-09T14:27:49Z</dc:date>
    <item>
      <title>What's the difference between an event and a log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478009#M192799</link>
      <description>&lt;P&gt;Can anyone explain me what's the difference between an event and a log. &lt;/P&gt;

&lt;P&gt;According to me, an event is set of logs generated after matching a correlation. &lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 20:03:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478009#M192799</guid>
      <dc:creator>aruncp333</dc:creator>
      <dc:date>2019-09-06T20:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between an event and a log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478010#M192800</link>
      <description>&lt;P&gt;An "event" is any one record returned from an index or search.  It could be a single log, or a single record that contains a count of logs, or a single record that says "100".&lt;/P&gt;

&lt;P&gt;A "log" is a specific type of event, specifically documenting that something happened at a particular time.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 20:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478010#M192800</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2019-09-06T20:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between an event and a log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478011#M192801</link>
      <description>&lt;P&gt;That's interesting, Dal. &lt;/P&gt;

&lt;P&gt;Further I have a follow up question. &lt;/P&gt;

&lt;P&gt;Question: How can I propose splunk sizing if the customer is having existing solution in terms of events per second (EPS). &lt;/P&gt;

&lt;P&gt;Let's say, 1000,000EPS conversion to Splunk/day license sizing. &lt;/P&gt;

&lt;P&gt;Thanks in advance. &lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2019 08:59:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478011#M192801</guid>
      <dc:creator>aruncp333</dc:creator>
      <dc:date>2019-09-07T08:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: What's the difference between an event and a log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478012#M192802</link>
      <description>&lt;P&gt;Really you have 3 terms &lt;CODE&gt;event&lt;/CODE&gt;, &lt;CODE&gt;log&lt;/CODE&gt;, and &lt;CODE&gt;result&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;An &lt;CODE&gt;event&lt;/CODE&gt; is a thing that happened anywhere at any time.  It might be in Splunk and it might not.  A &lt;CODE&gt;log&lt;/CODE&gt; is the &lt;CODE&gt;digital exhaust&lt;/CODE&gt; of that event; it is the plain-text vestige that indicates than an event happened.  A &lt;CODE&gt;result&lt;/CODE&gt; is each &lt;CODE&gt;thing&lt;/CODE&gt; that is returned from a Splunk search.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 14:27:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-s-the-difference-between-an-event-and-a-log/m-p/478012#M192802</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-09-09T14:27:49Z</dc:date>
    </item>
  </channel>
</rss>

