I am a grad student and I recently gave a quiz on splunk. There was a true/false question.
Q: Splunk Alerts can be created to monitor machine data in real-time, alerting of an event as soon as it logged by the host.
I marked it as false because it should be "as soon as the event gets indexed by Splunk" instead of "as soon as the event gets logged by the host".
I have raised a question because I was not awarded marks for this question. But the counter was "Per-result triggering helps to achieve this". But isn't it basic that Splunk can only read the indexed data? Can anyone please verify if I'm correct?
Thanks in advance.
Real-time searches see events before they are indexed.