Getting Data In

Indexed and not indexed data

gdfasdasd
Explorer

hello,

 

i am new in splunk. i can not understand if i not indexed data in can i search this data in Splunk? or only indexed data can i search in Splunk?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd,

only indexed data obviously!

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Strictly speaking, there are other ways to access non-indexed data such as DB Connect and inputlookup, but generally speaking you should index your data (as @gcusello suggested) in order to get powerful access to the information contained within it.

0 Karma

gdfasdasd
Explorer

Some forum i read that all data can search in splunk indexed or not indexed is it incorrect inforamtion?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

I don't know which forums are you speaking of,.

as also @ITWhisperer said, you can access external data without indexing them e.g. using DB-Connect (that's a  Splunk JDBC client to query Databases), but in this case, you have to forget performances from your system!

In Splunk you can mainly search only on indexed data.

Ciao.

Giuseppe

0 Karma

gdfasdasd
Explorer
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gdfasdasd ,

in the post is written also:  'if Splunk has the data - it is indexed and searchable', so only indexed data are searchable.

If you discard an event and you don't index it, you cannot search it.

So I confirm, that you can search only on indexed data, with the exception of DB-Connect with performances to forget.

Ciao.

Giuseppe

gdfasdasd
Explorer

i want to use Splunk as a log server. Send any data but filter they from index which do not pass license. if data not pass in indexer i can not search this data?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...