LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

What happens to data in Splunk at index time, and what happens at search time?

At index time Splunk reads raw data, classifies it by sourcetype, extracts timestamps, splits it into events and writes them to an index; at search time it retrieves those events, extracts fields from the raw text and transforms them with SPL into reports and visualisations.

Splunk index time (read, classify sourcetype, extract timestamp, break into events, store in index) then search time (retrieve, extract fields, SPL)

* Parsing into events happens once; field extraction happens at every search. *

Index time (when data arrives):

  1. Read data from a source on a host.
  2. Classify it as a sourcetype (e.g. linux_syslog, WinEventLog).
  3. Extract the timestamp.
  4. Apply line-breaking rules to split the stream into individual events.
  5. Write the events into an index on disk (by default the index main).

Search time (when you query):

  1. Retrieve matching events from disk.
  2. Extract fields from the raw text, based on configuration and user-defined patterns.
  3. Transform the results with SPL (Search Processing Language) into tables, statistics, charts and dashboards.

Because most field extraction happens at search time ("schema on read"), you can ingest data you do not fully understand yet and define fields later. The price is that searches do the parsing work every time they run.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026