I've been reading about the differences between forward indexes and inverted indexes. Which model does Splunk use? I have not been able to find that information in the documentation.
Hi @aznewman ,
Splunk uses a time series inverted index, in the form of .tsidx files:
https://docs.splunk.com/Splexicon:Tsidxfile
You can read more about how that index is built/populated here:
https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/Abouteventsegmentation