Getting Data In

Indexed and not indexed data

gdfasdasd
Explorer

hello,

 

i am new in splunk. i can not understand if i not indexed data in can i search this data in Splunk? or only indexed data can i search in Splunk?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd,

only indexed data obviously!

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Strictly speaking, there are other ways to access non-indexed data such as DB Connect and inputlookup, but generally speaking you should index your data (as @gcusello suggested) in order to get powerful access to the information contained within it.

0 Karma

gdfasdasd
Explorer

Some forum i read that all data can search in splunk indexed or not indexed is it incorrect inforamtion?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

I don't know which forums are you speaking of,.

as also @ITWhisperer said, you can access external data without indexing them e.g. using DB-Connect (that's a  Splunk JDBC client to query Databases), but in this case, you have to forget performances from your system!

In Splunk you can mainly search only on indexed data.

Ciao.

Giuseppe

0 Karma

gdfasdasd
Explorer
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

gdfasdasd
Explorer

i want to use Splunk as a log server. Send any data but filter they from index which do not pass license. if data not pass in indexer i can not search this data?

0 Karma