Getting Data In

How do Splunk indexers perform indexing without a parser or connector?

rajveeryadav04
New Member

Hi All,

Well, I am new to Splunk, but I have been working on other SIEM tools like RSA SA and QRadar. I just started to learn about Splunk.

Well I want to know about Splunk indexers and how indexing happens here?

Actually I have studied that Splunk doesn't need any parser or connector, so what I am not getting is, if there is no parser, then how is indexing happening? In all other tools, indexing is totally based on a parser. If a parser for a specific device is not available, then all logs from that device will come under unknown device.

Maybe my question looks a bit stupid. Sorry for that, but I really want to know how indexers works and how it identifies devices and applications without any parser for that..

Hope you understand my query, waiting for an answer...

Thanks in advance.

Regards,
Rajbir

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...