DBDB.io The Encyclopedia of Database Systems · Est. 2017
Database of Databases

Database Entry

Splunk


Splunk is a database system designed for extracting structure and analyzing machine-generated data. It takes in data from other databases, web servers, networks, sensors, etc. and then offers services to analyze the data, and produce dashboards, graphs, reports, alerts, and other visualizations. All this data is captured in a searchable repository and served via a web interface called Splunk Web. [04][05]

Developer
Country of Origin
US
Start Year
2002 [06]
Project Type
Commercial
Written in
C++
Supported Languages
C#, Java, JavaScript, PHP, Python, Ruby
License
Proprietary

Splunk is a horizontal application and is used by a large and diverse set of users with different knowledge bases in an organization to monitor IT operations, security, and business analytics. It is also possible to extend the Splunk environment by installing or developing an app. An app runs on the Splunk platform and includes inputs, lookups, and reports to display information about the data to add specific functionality. Over 90 of the Fortune 100 companies use Splunk.

Database Entry

Splunk


Splunk is a database system designed for extracting structure and analyzing machine-generated data. It takes in data from other databases, web servers, networks, sensors, etc. and then offers services to analyze the data, and produce dashboards, graphs, reports, alerts, and other visualizations. All this data is captured in a searchable repository and served via a web interface called Splunk Web.

Splunk is a horizontal application and is used by a large and diverse set of users with different knowledge bases in an organization to monitor IT operations, security, and business analytics. It is also possible to extend the Splunk environment by installing or developing an app. An app runs on the Splunk platform and includes inputs, lookups, and reports to display information about the data to add specific functionality. Over 90 of the Fortune 100 companies use Splunk.[04][05]

History[06][07][08][09][10][11]


Splunk was founded by Erik Swan, Michael Baum, and Rob Das in 2002. Prior to founding Splunk, all three founders were dealing with large-scale search infrastructures and were unhappy about the tools available for analyzing log files at the time. Early customers of Splunk reported their experience of debugging their environments as ‘digging through caves’ and ‘crawling through the muck to find the problems’, which inspired the founders to name the company after the word for exploration of caves, spelunking.

Splunk raised a $5 million Series A in 2004 led by August Capital and reached profitability by 2009. Splunk went public on NASDAQ under the ticker name SPLK at a price of $17 a share in 2012. Splunk acquired SignalFx, a cloud monitoring platform for infrastructure, microservices, and applications, in August 2019 for $1.1 billion.

Checkpoints[12]


Splunk supports the notion of checkpoints. When reading data and indexing, a checkpoint can be created to mark the data as being read or indexed.

Compression[13][14]


Splunk compresses the raw data up to approximately half its original size. For indexes, Splunk supports gzip (default), lz4, and zstd for compression and can handle different buckets compressed with different algorithms.

Concurrency Control[15]


Splunk supports concurrent search but limits the number in order to preserve performance. It also allows you to configure the maximum number of concurrent searches between scheduled and summarization queries based on your usage.

Splunk also supports concurrent users. A user uses exactly one CPU core on each indexer for the duration of the search. By default, a search on Splunk cannot use multiple cores.

Data Model[16][17]


Splunk is a NoSQL database management system. Its data model is a hierarchical search-time mapping of data. The knowledge managers on a Splunk instance design the data model.

Foreign Keys[18]


Splunk supports referential integrity.

Hardware Acceleration[19][20]


FPGA and GPU can be used to accelerate Splunk's performance.

Indexes[21][22]


Splunk adds all incoming data to indexes after processing it. It indexes data by breaking them into events, based on the timestamp. After breaking the data up into events, the events are passed through the indexing pipeline where additional steps are taken, such as breaking the events into segments so indexing and searching can be done efficiently, building data structures for the indexes, and writing the events out to disk.

Splunk supports events and metrics indexes. Events indexes are the default index type, impose minimal structure, and can accommodate any type of data. Metrics indexes are highly structured and designed to handle high volume and low latency demands. These indexes have better performance and less space utilization compared to events indexes.

Isolation Levels[23]


In Splunk, workload management allows resource isolation search and ingest processes. This lets users allocate resources to search pools without affecting ingest processes.

Joins[24]


Splunk supports inner (default), outer, and left joins using the join command. This works best when the results of the subsearch are less than 50,000 rows.

It can also join a search result set with itself using the selfjoin command.

Logging[25]


Scripts in Splunk can send logging data to splunkd.log for tracking and troubleshooting using the stderr command. It supports 5 log levels: * DEBUG * INFO * WARN * ERROR (default) * FATAL

Query Execution[26]


Splunk uses MapReduce to speed up searches.

Storage Architecture[27]


Splunk is disk-oriented.

Storage Model[28]


Splunk stores data in a flat file format. All data in Splunk is stored in an index and in Hot, Warm, and Cold buckets depending on the size and age of the data. It supports both clustered and non-clustered indexes.

Views[29]


Splunk's Web Framework includes a library of views (such as Chart, Table, SplunkMap, Timeline, etc.), UI widgets that allow you to display certain data in certain ways.

Citations

29 sources
  1. Splunk | Unified Security & Observability for Digital Resilience splunk.com
  2. Splunk® Enterprise - Splunk Documentation splunk.com
  3. Splunk - Wikipedia wikipedia.org
  4. https://www.crunchbase.com/organization/splunk crunchbase.com
  5. About Splunk Enterprise - Splunk Documentation splunk.com
  6. https://www.splunk.com/view/SP-CAAAGBY splunk.com Dead — Check Archive
  7. https://www.crunchbase.com/organization/splunk#section-funding-rounds crunchbase.com
  8. IT search company Splunk reaches profitability | VentureBeat venturebeat.com Dead — Check Archive
  9. Splunk Soars as Investors Embrace Data Boom - The New York Times nytimes.com
  10. https://www.crunchbase.com/organization/signalfuse crunchbase.com
  11. Splunk Inc.’s Splunk Data Center Search Party – Computerworld computerworld.com
  12. Data checkpoints | Splunk Enterprise, Splunk Cloud Platform (last updated 2026-05-09T14:22:44.562Z) splunk.com
  13. How Splunk Enterprise calculates disk storage - Splunk Documentation splunk.com
  14. indexes.conf - Splunk Documentation splunk.com
  15. Set limits for concurrent scheduled searches | Splunk Cloud Platform (last updated 2026-05-14T14:02:03.551Z) splunk.com
  16. About data models - Splunk Documentation splunk.com
  17. Splunk System Properties db-engines.com
  18. Release Notes for Splunk Enterprise Security - Splunk Documentation splunk.com
  19. https://2018gputechconf.smarteventscloud.com/connect/sessionDetail.ww?SESSION_ID=152351 smarteventscloud.com Dead — Check Archive
  20. How Ryft Uses AWS’s Reprogrammable Chips for Big Data Analytics in Hyb datacenterknowledge.com
  21. Indexes, indexers, and indexer clusters - Splunk Documentation splunk.com
  22. Command line tools for use with Support - Splunk Documentation splunk.com
  23. How workload management works - Splunk Documentation splunk.com
  24. join - Splunk Documentation splunk.com
  25. Set up logging - Splunk Documentation splunk.com
  26. Technical introduction to Splunk | DBMS 2 : DataBase Management System Services dbms2.com
  27. Reference hardware - Splunk Documentation splunk.com
  28. Solved: Where exactly and how is the data stored in splunk... - Splunk Community splunk.com
  29. Splunk views | Documentation | Enterprise | Splunk Developer Program splunk.com
Revision #12