N
non-searchable
A non-searchable copy of an indexer cluster bucket is a copy that contains only the rawdata file and not the index files . Therefore, it is not immediately searchable. Non-searchable copies takes up less disk space than searchable copies, but they require significant processing time to be made searchable.
Related Products: Platform
Related Terms: searchability, searchable
non-streaming command
A non-streaming command waits until all of the events are gathered from the indexers before the command runs. For example, the sort command must have the entire set of events before the events can be sorted. Non-streaming commands run on the search head. By contrast, a streaming command operates on each event as the event is returned by the search. Any command in a search that occurs after a non-streaming command must also be processed on the search head.
Related Products: Platform
Related Terms: streaming command, search head
normalized score
The score of an indicator assigned by Threat Intelligence Management to show the relative severity of the indicator. Normalized scoring automatically converts a set of scores into a single value that reflects the original score, or passthru score , of the indicator.
Related Products: Platform
Related Terms: risk score
notable event
An event generated by a correlation search as an alert . A notable event includes custom metadata fields to assist in the investigation of the alert conditions and to track event remediation. This term applies to Splunk Enterprise Security, the Splunk App for PCI Compliance, and Splunk IT Service Intelligence.
Related Products: Platform, Enterprise Security, IT Service Intelligence
Related Terms: risk notable
nullQueue
A Splunk Enterprise null device that is equivalent to /dev/null on *nix operating systems. Splunk Enterprise sends unwanted incoming events to nullQueue to discard them during data routing and filtering .
Related Products: Platform