Is it possible to skip the default indexing that happens in splunk. I would like to get the raw data back without indexing it.
Are you saying that you want each input source to be a single event?
Perhaps I don't understand the question, but indexing is what makes it possible to get the raw data back. Splunk can't find your data without the index.
Describe your use case from a more abstract point of view.
The splunk indexer convert the raw data into separate events to store it in its database or forward it. What i want is to skip the default indexing. I want the raw data not to be converted into events. Is it a posiblity?