Understanding Splunk indexes
An index is a specific type of data storage inside Splunk Enterprise; in other words, to keep it simple, an index is a repository of data. For example, you are searching for your address on a form online and you input your address details: you provide your house number, your street, and your postcode, which is unique to you. Similarly, if you want to search for specific data in Splunk, you can find it by using its index.
There are two types of Splunk indexes. They are called event indexes and metrics indexes. Event indexes store any type of text data, and this is the default index type. Metrics indexes only store metrics data, which must comply with a defined structure. There are special commands in Splunk, usually prefixed with m
such as mstats
, mpreview
, and mcatalog
, for working with metrics data. Metrics indexes are a completely different topic and beyond the scope of this book. If you would like to read more about them, please visit https://tinyurl...