Getting Data In

Is it possible to skip the default indexing in splunk?

saipavan
Explorer

Is it possible to skip the default indexing that happens in splunk. I would like to get the raw data back without indexing it.

Tags (1)
0 Karma

lguinn2
Legend

Are you saying that you want each input source to be a single event?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps I don't understand the question, but indexing is what makes it possible to get the raw data back. Splunk can't find your data without the index.

---
If this reply helps you, Karma would be appreciated.
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Describe your use case from a more abstract point of view.

0 Karma

saipavan
Explorer

The splunk indexer convert the raw data into separate events to store it in its database or forward it. What i want is to skip the default indexing. I want the raw data not to be converted into events. Is it a posiblity?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...