What is the name of the object that stores events inside of an index?
A bucket is the object that stores events inside of an index.According to the Splunk documentation1, ''An index is a collection of directories, also called buckets, that contain index files.Each bucket represents a specific time range.'' A bucket can be in one of several states, such as hot, warm, cold, frozen, or thawed1.Buckets are managed by indexers or clusters of indexers1.
Limited Time Offer
25%
Off
Currently there are no comments in this discussion, be the first to comment!
Currently there are no comments in this discussion, be the first to comment!