Hello!
I've been reading about Splunk Enterprise being 'schema on read' and the Elastic Stack being 'schema on write'. I.e. Splunk SPL parses/formats/enriches machine data in query time as opposed to doing it in index time as with Elasticsearch. This is stated in several articles on the internet but I can't seem to find any information about this in Splunk's official documentation? I would greatly appreciate it if someone pointed me in the right direction.
Take a look at this on Splunk's data pipeline: https://docs.splunk.com/Documentation/Splunk/7.2.5/Deploy/Datapipeline