Splunk can do a lot. I know that's really specific... but it's also a very accurate statement. An important part of understanding Splunk is really grasping how Splunk handles your data, or “data lifecycle” (if you’re into fancy words).
Splunk does a great job of documenting their stuff. So you shouldn't ever be too confused about how a function works, and so on. Having said this, however, the issue we’ve run across is sometimes... well, sometimes they tend to use a lot of words and it can get messy.
So, we’ve put together an infographic-style piece that illustrates the Splunk data lifecycle based on their Splunk wiki entry. Hopefully it helps to make a very text-heavy process more visual in nature and a little clearer. Enjoy!