CARVIEW |
event processing
event processing
noun
Event processing covers everything that happens to your data between the time you define an input and the time the data appears in the Splunk index. At index time, Splunk software organizes and structures your data, including processing multiline events, extracting important fields such as the timestamp, and compressing the data.
The Splunk Web data preview tool is available in both Splunk Enterprise and Splunk Cloud Platform. Data preview lets you configure the format of your event data before processing. Use it to see how your processed events will look and make adjustments to improve the formatting of the data.
In Splunk Enterprise, you can configure and customize event processing using configuration files.
After the data is in the index, you can add additional knowledge to your events, such as fields, tags, and event types.
For more information
In Getting Data In:
- saved search
- scheduled alert
- scheduled report
- scheduled search
- scheduler
- scripted authentication
- scripted input
- search
- search affinity
- Search app
- search artifact
- search assistant
- search execution directive
- search factor
- search field
- search filter
- search head
- search head cluster
- search head cluster captain
- search head cluster member
- search head clustering
- search head pooling
- search head targeting
- search job
- Search Job Inspector
- search macro
- search management
- search mode
- search peer
- search peer replication
- Search Processing Language
- search scheduler
- search time
- search timeline
- search view
- searchability
- searchable
- segment
- send to background
- sequence template
- series
- server
- server class
- Settings
- SignalFlow
- SignalFx Smart Agent receiver
- Simple XML
- single-instance deployment
- single-site indexer cluster
- SmartStore
- source
- source type
- span
- span tag
- SPL
- SPL2
- SPL2 statement
- Splunk Answers
- Splunk Distribution of OpenTelemetry Collector
- Splunk OpenTelemetry Collector
- Splunk platform
- Splunk UI
- Splunk Web
- Splunk Web Framework
- Splunkbase
- splunkd
- SplunkJS Stack
- stack mode
- standalone search head
- stanza
- static captain
- streaming command
- subsearch
- summary index