Training + Certification

Splunk Fundamental

bhavin_crest
Explorer

Difference between parsed and indexed data in SPLUNK

Tags (1)
0 Karma
1 Solution

gcusello
Legend

Hi @bhavin_crest,
parsing and Indexing are two different phases of the ingestion pipeline.
Here you can find a description https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/Howindexingworks

In few words:

  • during parsing is prepared all that will be indexed (fields, econding, etc...),
  • during indexing Splunk write the raw data and index files to disk.

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
Legend

Hi @bhavin_crest,
parsing and Indexing are two different phases of the ingestion pipeline.
Here you can find a description https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/Howindexingworks

In few words:

  • during parsing is prepared all that will be indexed (fields, econding, etc...),
  • during indexing Splunk write the raw data and index files to disk.

Ciao.
Giuseppe

View solution in original post

0 Karma