This is the query language used to search, analyze, transform, and visualize data inside Splunk
SPL (Search Processing Language)
This built-in logging system in that records system, security, and application events
Windows Event Log
This is a Splunk component that collects data and sends it to Slunk
Forwarder
This field is the device name
host
This provides visual insights
This is a security solution category that collects, analyzes, and correlates log and event data from across an organization to detect threats and support incident response.
SIEM (Security Information + Event Management)
This is a text-based data format that stores information in key-value pairs and structured objects.
JSON
This is a lightweight forwarder (small CPU/memory footprint)
Universal Forwarder (UF)
This field is the data sources
source
This is a search that can be reused
Reports
This is a set of rules and endpoints that allows other systems, tools, or applications to interact with Splunk programmatically instead of using the Splunk web interface.
API (Application Programming Interface)
This is the default logging framework used to record system and application activity.
Linux syslogs
This can collect and forward only
Universal Forwarder (UF)
This field is Format/type of data
sourcetype
This notifies users when conditions are met
Alerts
This is a security platform that automates and coordinates incident response workflows so security teams can respond to threats faster and more consistently.
SOAR (Security Orchestration, Automation, and Response)
What are services that provide computing, storage, networking, and applications over the internet.
Cloud Platform
This can filter, parse, and route data
Heavy Forwarder (HF)
This field is a storage location
index
This is beneficial because of consistent results, dashboard integration, and easy sharing.
Reports
This is a standard data model that normalizes and organizes data into consistent field names and categories so different data sources can be searched and correlated in a uniform way.
CIM (Common Information Model)
This is the core system log that Splunk ingests to provide visibility into system activity, security events and operational health.
Linux syslogs
This can deploy to thousands of endpoints
Universal Forwarder (UF)
_time
This can display reports, charts, tables, and metrics.
Dashboard