hello,
i am new in splunk. i can not understand if i not indexed data in can i search this data in Splunk? or only indexed data can i search in Splunk?
Hi @gdfasdasd ,
in the post is written also: 'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.
If you discard an event and you don't index it, you cannot search it.
So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.
Ciao.
Giuseppe
Strictly speaking, there are other ways to access non-indexed data such as DB Connect and inputlookup, but generally speaking you should index your data (as @gcusello suggested) in order to get powerful access to the information contained within it.
Some forum i read that all data can search in splunk indexed or not indexed is it incorrect inforamtion?
Hi @gdfasdasd ,
I don't know which forums are you speaking of,.
as also @ITWhisperer said, you can access external data without indexing them e.g. using DB-Connect (that's a Splunk JDBC client to query Databases), but in this case, you have to forget performances from your system!
In Splunk you can mainly search only on indexed data.
Ciao.
Giuseppe
https://community.splunk.com/t5/Splunk-Search/Searching-data-that-is-not-indexed/m-p/557435
i read this information
Hi @gdfasdasd ,
in the post is written also: 'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.
If you discard an event and you don't index it, you cannot search it.
So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.
Ciao.
Giuseppe
i want to use Splunk as a log server. Send any data but filter they from index which do not pass license. if data not pass in indexer i can not search this data?