Getting Data In

Indexed and not indexed data

gdfasdasd
Explorer

hello,

 

i am new in splunk. i can not understand if i not indexed data in can i search this data in Splunk? or only indexed data can i search in Splunk?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd,

only indexed data obviously!

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Strictly speaking, there are other ways to access non-indexed data such as DB Connect and inputlookup, but generally speaking you should index your data (as @gcusello suggested) in order to get powerful access to the information contained within it.

0 Karma

gdfasdasd
Explorer

Some forum i read that all data can search in splunk indexed or not indexed is it incorrect inforamtion?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

I don't know which forums are you speaking of,.

as also @ITWhisperer said, you can access external data without indexing them e.g. using DB-Connect (that's a  Splunk JDBC client to query Databases), but in this case, you have to forget performances from your system!

In Splunk you can mainly search only on indexed data.

Ciao.

Giuseppe

0 Karma

gdfasdasd
Explorer
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

gdfasdasd
Explorer

i want to use Splunk as a log server. Send any data but filter they from index which do not pass license. if data not pass in indexer i can not search this data?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...