Getting Data In

Indexed and not indexed data

gdfasdasd
Explorer

hello,

 

i am new in splunk. i can not understand if i not indexed data in can i search this data in Splunk? or only indexed data can i search in Splunk?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd,

only indexed data obviously!

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Strictly speaking, there are other ways to access non-indexed data such as DB Connect and inputlookup, but generally speaking you should index your data (as @gcusello suggested) in order to get powerful access to the information contained within it.

0 Karma

gdfasdasd
Explorer

Some forum i read that all data can search in splunk indexed or not indexed is it incorrect inforamtion?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

I don't know which forums are you speaking of,.

as also @ITWhisperer said, you can access external data without indexing them e.g. using DB-Connect (that's a  Splunk JDBC client to query Databases), but in this case, you have to forget performances from your system!

In Splunk you can mainly search only on indexed data.

Ciao.

Giuseppe

0 Karma

gdfasdasd
Explorer
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

gdfasdasd
Explorer

i want to use Splunk as a log server. Send any data but filter they from index which do not pass license. if data not pass in indexer i can not search this data?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...