Add Data: Monitor option
Monitor files, directories, HTTP events, TCP/UDP, Scripts
Add Data: Forward option
Receive data from external forwarders
App context
Tells splunk which app to apply source type to.
Reasons to have separate indexes
Faster searches (narrower searches)
Limit access by user role
Set different retention policies
Main input source
Forwarders