Glossary
A glossary of technical terms specific to Imply Lumi, and some related terms in third-party products.
Deployment options
Lumi Cloud
A highly available, fully managed SaaS deployment of Lumi hosted by Imply. Your data resides in the Imply AWS environment, and Imply operates the infrastructure, updates, scaling, security, and compliance.
Lumi Enterprise
A self-managed deployment of Lumi that runs in your own cloud environment, keeping your data within your own infrastructure. You manage the infrastructure, scaling, security, and compliance, and you apply upgrades on a schedule you determine.
Product areas
Lumi API
The programmatic interface for Lumi.
Lumi query syntax
The formal structure for Lumi queries against your event data. Contrast with Splunk® Search Processing Language (SPL).
Lumi UI
The Lumi web application where you can configure integrations, search for events, and perform Lumi administration tasks.
Concepts
integration
Method for connecting to an external system from Lumi. There are two types of integrations: ingestion and application.
ingestion integration
An integration that allows a third-party application to send events to Lumi. An ingestion integration consists of a receiver and an IAM key.
application integration
An integration with a third-party application to access events within Lumi.
pipeline
A pipeline is an ordered list of event processors that operate on a set of events resulting from a user-defined search query.
predefined pipeline
A set of standard processors included with Lumi to parse and transform events with a specific data format.
processor
An event processor is a rule for event transformation. For example adding, removing, overriding, or otherwise modifying event metadata.
Data management
cold start
The delay on the first query after a virtual compute pool has been idle, while Lumi provisions compute resources and loads the data it needs into virtual storage. To avoid the delay for time-sensitive queries, issue a warm-up query in advance.
default pool
The first virtual compute pool you create, which Lumi uses to serve queries across both hot and virtual storage as needed. Application integrations that don't use federated search always route queries to the default pool.
deletion rule
A rule that sets how long Lumi retains managed data before deleting it. Deletion rules take precedence over tiering rules.
external data
Data that stays in your own Amazon S3 storage and that Lumi queries without ingesting. Lumi indexes the data, leaves the source in your bucket, and serves queries on demand through the virtual tier. You query external data through Splunk federated search only. Contrast with managed data.
external data connection
A configured link between Lumi and your S3 storage that makes external data queryable. Each connection points Lumi at a logs location to read and an index location where Lumi writes its index.
external data index
The index Lumi builds for an external data connection and writes to the index location you configure for the connection. Lumi queries this index to serve external data on demand, without ingesting your source data. Don't confuse it with the Lumi index attribute or a Splunk index.
managed data
Data ingested into Lumi and held in storage that Lumi manages. Lumi copies managed data to the hot tier by default, and tiering rules and deletion rules apply to it. Contrast with external data.
tier
A combination of storage and compute resources that determines how data is cached and made available for querying.
hot tier
The default tier where Lumi caches ingested data. It consists of persistent cache (hot storage) and persistent compute resources that deliver consistent query performance with low latency and high concurrency.
virtual tier
A cost-efficient alternative to the hot tier that is suitable for infrequently accessed data. It consists of a transient cache (virtual storage) that loads data on demand and virtual compute resources that spin up to serve queries against virtual storage. The virtual tier also serves queries against external data.
tiering rule
A rule that sets how long managed data matching an index stays in the hot tier before it's removed. Once removed, the data becomes accessible through the virtual tier. If two rules target the same index, Lumi applies the rule with the longest retention period.
t-shirt size
A configuration that determines the capacity of a virtual compute pool, based on instance type, node count, and maximum concurrency level.
predefined t-shirt size
A t-shirt size that Lumi provides by default. Predefined t-shirt sizes let you choose a pool's capacity without configuring each setting individually.
custom t-shirt size
A t-shirt size you define, specifying the instance type, node count, and query concurrency. Custom t-shirt sizes are available in Lumi Enterprise only. Once configured, custom t-shirt sizes replace predefined t-shirt sizes entirely.
virtual compute pool
Transient compute resources that Lumi provisions on demand to serve queries against data outside the hot tier. Lumi spins up a pool when a query targets data served by the virtual tier, and shuts it down after the maximum idle time you configure.
Events
agent
A software component deployed within a service to send events to an event collector.
For example: Open Telemetry (OTel), StatsD, Prometheus, Splunk forwarders.
attribute
Attributes are Lumi event metadata.
IAM key attribute
A setting stored with an IAM key to configure event ingestion for designated integrations. These settings include metadata for user attributes, system attributes, event parsing, and ingestion configuration. IAM key attributes can be global, which apply to all ingestion integrations, or specific to certain integrations.
index attribute
A notable user attribute in Lumi. You can set the value of the index attribute for events to configure federated search in Splunk. Don't confuse it with a Splunk index or the external data index Lumi builds for an external data connection. Learn more in Imply Lumi concepts for Splunk users.
user attribute
An attribute derived from a raw event, added by an upstream agent, specified in Lumi, or assigned by Lumi.
system attribute
A system-defined attribute, usually extracted from a Lumi component such as the event collector, a receiver, or an API key.
event collector
A Lumi microservice that receives, processes, and publishes data from external ecosystems such as Splunk. For Splunk integrations, the event collector receives data from Splunk forwarders, transforms it into the Lumi event model, and publishes the transformed events to a Kafka topic for downstream ingestion into Apache® Druid.
event
A unit of data in Lumi, including data destined for but not yet processed by Lumi. Also refers to data destined for, but not yet processed by, Lumi.
enriched event
An event that includes metadata from event processing systems like an agent or attributes in Lumi.
raw event
An event in its original state without any formal changes or additional metadata from event processing systems.
exporter
A Kafka exporter that publishes processed events to a Kafka topic for downstream ingestion.
receiver
Lumi service that accepts incoming data like events or search requests. During event processing, Lumi adds receiver information to the event as a system attribute.
send events
The process by which an agent or a forwarder adds events to Lumi.
Third-party terms
add-on
Software that configures a Splunk deployment to connect to Lumi, add events, and query events.
Splunk term: add-on.
forwarder
A Splunk instance that forwards data to another Splunk instance or to a third-party system. Lumi uses the universal forwarder and heavy forwarder.
Splunk term: forwarder
heavy forwarder
A Splunk forwarder that has the functionality of the universal forwarder and can also index, transform, and route data.
Splunk term: heavy forwarder
universal forwarder
A Splunk forwarder that contains only the essential components needed to forward data.
Splunk term: universal forwarder
Search
explore
The explore screen in the Lumi UI.
federated search
Method for searching Lumi events from Splunk using SPL, so you can analyze Lumi events alongside your Splunk data. Lumi supports two federated search modes: standard and transparent. For the Splunk definition of the term, see federated search.
standard mode
A federated search mode that routes queries through a Splunk federated index to a Lumi index.
Standard mode requires the federated: query prefix and gives you explicit control over which federated indexes you query.
It doesn't support data models or lookups.
transparent mode
A federated search mode that queries Lumi indexes directly, without the federated: query prefix and without a federated index to configure.
Transparent mode is required for data model queries and lookups.
search head
The software service that handles search requests and directs search results back to the user. In federated search we refer to Splunk as the federated search head and Lumi as the remote search head.
Third-party terms
federated search
Unified search across Splunk deployments.
Splunk term: federated search.
Search Processing Language (SPL)
A set of commands used to search Splunk data.
Splunk terms: SPL, SPL2.
Splunk index
The repository for Splunk data.
Not the same as the Lumi index attribute or an external data index.
Splunk term: index.
Send
S3 pull
A Lumi integration that ingests events from objects stored in an Amazon S3 bucket.
S3 routing
A Lumi integration that ingests events from Splunk through an Amazon S3-compatible endpoint in Lumi. The integration uses a Splunk ingest action as an intermediate forwarding layer.
Administration
account
A centralized view in the Lumi UI for managing company and billing information.
cloud region
The geographical area or areas linked to an account.
Related to cloud regions such as us-east-1.
company
A corporate entity associated with one or more Lumi accounts.
IAM key
An API key in Lumi. You can use IAM keys for querying integrations and managing Lumi resources programmatically with the Lumi API. IAM keys consist of an ID and a token. A key's virtual tier access determines which virtual compute pool serves its queries against data outside the hot tier. A key can use only one pool, and a key without virtual tier access can query the hot tier only. A single key can't query both managed data and external data.
active key
An IAM key that has been used to add or search events in the past 24 hours.
inactive key
An IAM key that hasn't been used to add or search events in the past 24 hours.
permission
An ability to perform a specific task in Lumi. Permissions are allocated to roles which are assigned to users.
role
A collection of permissions, often identified by function within a company, assigned to one or more users.
user
An individual who performs tasks in Lumi. Users are linked to roles which convey the permissions to perform tasks.