Splunk Search

How do real-time searches identify both index and search-time fields if it processes data that hasn't been indexed yet?


I have gone through the Splunk Docs. It's saying that real-time search is basically used to search events before they get indexed. However, I need a few clarifications on this one below.

RT search processes un-indexed data. So, how could it identify the both index-time and search-time fields? Will it process the field extractions once it finds a match in incoming events?

The data is not indexed yet. So how it could look for its sourcetype, source, and host since all are index-time only?

Could someone explain in detail?

Thanks in advance

0 Karma


You are correct in that real-time searches grab the data before it hits the index queue, however real-time searches do have access to search time field extractions which happen in the parsing queue.

When events reach splunk, it goes thru different stages/pipeline which is explained detailed here


Also look at http://wiki.splunk.com/Community:HowIndexingWorks

A good read about real time searches are


State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!