Getting Data In

Indexed and not indexed data

gdfasdasd
Explorer

hello,

 

i am new in splunk. i can not understand if i not indexed data in can i search this data in Splunk? or only indexed data can i search in Splunk?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd,

only indexed data obviously!

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Strictly speaking, there are other ways to access non-indexed data such as DB Connect and inputlookup, but generally speaking you should index your data (as @gcusello suggested) in order to get powerful access to the information contained within it.

0 Karma

gdfasdasd
Explorer

Some forum i read that all data can search in splunk indexed or not indexed is it incorrect inforamtion?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

I don't know which forums are you speaking of,.

as also @ITWhisperer said, you can access external data without indexing them e.g. using DB-Connect (that's a  Splunk JDBC client to query Databases), but in this case, you have to forget performances from your system!

In Splunk you can mainly search only on indexed data.

Ciao.

Giuseppe

0 Karma

gdfasdasd
Explorer
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

gdfasdasd
Explorer

i want to use Splunk as a log server. Send any data but filter they from index which do not pass license. if data not pass in indexer i can not search this data?

0 Karma
Get Updates on the Splunk Community!

Meet Duke Cyberwalker | A hero’s journey with Splunk

We like to say, the lightsaber is to Luke as Splunk is to Duke. Curious yet? Then read Eric Fusilero’s latest ...

The Future of Splunk Search is Here - See What’s New!

We’re excited to introduce two powerful new search features, now generally available for Splunk Cloud Platform ...

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...