Splunk Search

What is the search engine Splunk uses to retrieve the data instantly ?

Rshekar19
New Member

I need to understand the backend search engine Splunk uses to retrieve the data instantly upon a search in the UI.
Also how the data is stored in the splunk servers.
We send data to splunk servers in our project and we request splunk team to create indexes, sources, source types based on our applications. Then we create field aliases, alerts, reports etc using UI. I need to know how the data (transaction log, json etc) we push to splunk is stored in Splunk. Also what volume of data can be stored in splunk and retrieved instantly.
Does Splunk has similarity with hadoop system?

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

It's flat files with an index, and is proprietary. The Splunk Documentation has the answer to pretty much every question you have, at least insofar as you actually need to know it. It'll tell you how it stores the data, how data moves through the pipelines to be stored, how searches work, how they work in a distributed environment and so on.

To get you started, here's Splunk does with your data when you get it in and how Splunk stores that data. I recommend reading those and following links, and perhaps asking more questions as you come across them. But really, it is fairly well documented so I'd start there.

"How much data"? Well, "instant" is relative. There are people reasonably happy with their search speeds who have hundreds of TB or even petabytes. They use indexer clusters, and sometimes search head clusters (both in the docs!), then may spend some time making sure they're writing smart searches. For what its worth, this is no different than a larger SQL instance or any other large, data-sourced program - you just need enough hardware, then DBAs (or in this case Splunk folks) to optimize your queries (searches).

Happy Splunking!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...