Getting Data In

Is it possible to skip the default indexing in splunk?

saipavan
Explorer

Is it possible to skip the default indexing that happens in splunk. I would like to get the raw data back without indexing it.

Tags (1)
0 Karma

lguinn2
Legend

Are you saying that you want each input source to be a single event?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps I don't understand the question, but indexing is what makes it possible to get the raw data back. Splunk can't find your data without the index.

---
If this reply helps you, Karma would be appreciated.
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Describe your use case from a more abstract point of view.

0 Karma

saipavan
Explorer

The splunk indexer convert the raw data into separate events to store it in its database or forward it. What i want is to skip the default indexing. I want the raw data not to be converted into events. Is it a posiblity?

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...