N

non-searchable

A non-searchable copy of an indexer cluster bucket is a copy that contains only the rawdata file and not the index files . Therefore, it is not immediately searchable. Non-searchable copies takes up less disk space than searchable copies, but they require significant processing time to be made searchable.

Related Products: Platform

Related Terms: searchability, searchable

non-streaming command

A non-streaming command waits until all of the events are gathered from the indexers before the command runs. For example, the sort command must have the entire set of events before the events can be sorted. Non-streaming commands run on the search head. By contrast, a streaming command operates on each event as the event is returned by the search. Any command in a search that occurs after a non-streaming command must also be processed on the search head.

Related Products: Platform

Related Terms: streaming command, search head

normalized score

The score of an indicator assigned by Threat Intelligence Management to show the relative severity of the indicator. Normalized scoring automatically converts a set of scores into a single value that reflects the original score, or passthru score , of the indicator.

Related Products: Platform

Related Terms: risk score

notable event

An event generated by a correlation search as an alert . A notable event includes custom metadata fields to assist in the investigation of the alert conditions and to track event remediation. This term applies to Splunk Enterprise Security, the Splunk App for PCI Compliance, and Splunk IT Service Intelligence.

Related Products: Platform, Enterprise Security, IT Service Intelligence

Related Terms: risk notable

nullQueue

A Splunk Enterprise null device that is equivalent to /dev/null on *nix operating systems. Splunk Enterprise sends unwanted incoming events to nullQueue to discard them during data routing and filtering .

Related Products: Platform