Knowledge Management

Forward index or inverted index- Which model does Splunk use?

aznewman
New Member

I've been reading about the differences between forward indexes and inverted indexes.  Which model does Splunk use?  I have not been able to find that information in the documentation.

Labels (2)
0 Karma

chaker
Contributor

Hi @aznewman ,

Splunk uses a time series inverted index, in the form of .tsidx files:

https://docs.splunk.com/Splexicon:Tsidxfile

You can read more about how that index is built/populated here:

https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/Abouteventsegmentation

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...