Match each Splunk search mode to its behavior.
Drag a concept onto its matching description — or click a concept then click the description.
Optimizes for speed, may skip event data
Balances speed and completeness (default)
Returns all available fields for each event
Searches data as it is indexed
Searches data already indexed
Why these pairings
Search modes control Splunk's behavior: Fast for speed (summary data), Verbose for completeness (all data), Smart as default balance. Common confusions involve swapping these definitions.