Why is the Splunk Web service not running after an upgrade to 6.2? Learn more »
Splunk does not use arealtional database to store events and indexes.
The storage is all flat file based.
Please have a look here:
Hope that answers your question?
is it mean, Splunk develop its own system to do this from ZERO? And it is really does not have any kind direct/significant relation to other DB technology?
I think Splunk might be using Lucene as a backend seach engine, though I am not sure, and looking for a confirmation.