<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where is my data get stored in Splunk ? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90620#M3308</link>
    <description>&lt;P&gt;Data is stored in &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk&lt;/CODE&gt;, one directory per index (&lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; being where Splunk was installed). The files in the respective directories hold the data in the indexes. The data in these files is not meant to be read directly - it would be very much like trying to read MySQL's database files directly expecting to be able to make sense of them.&lt;/P&gt;

&lt;P&gt;EDIT: Upon reading the link, this is already explained there. Where is it you get confused? What are you trying to do and why?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2013 18:57:21 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-08-06T18:57:21Z</dc:date>
    <item>
      <title>Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90617#M3305</link>
      <description>&lt;P&gt;Splunk receives raw data. Splunk indexer will index the data to Series of Events.&lt;BR /&gt;
Both the raw data and also the indexed data will be present in the Splunk later.&lt;/P&gt;

&lt;P&gt;Ques :&lt;BR /&gt;
1.Where do these data get stored ?&lt;BR /&gt;
2.Why we need to store raw data once it get indexed ?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2013 10:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90617#M3305</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-01-17T10:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90618#M3306</link>
      <description>&lt;P&gt;The chances of the same question being posted by multiple people seems pretty unlikely and given how often this happens - why post under many usernames?&lt;/P&gt;

&lt;P&gt;Anyway, to the problem at hand. Did you try the documentation? A quick search reveals;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Indexer/HowSplunkstoresindexes"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/Indexer/HowSplunkstoresindexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This is very comprehensive and theres little point in me summarising it here, if you read it then you'll have a complete understanding of how Splunk stores and where it stores this data.&lt;/P&gt;

&lt;P&gt;The rawdata is needed to rebuild the metadata should the buckets ever become corrupted or unable to be read by Splunk, this is also important in a clustered environment where you can choose how many copies of the raw data are available for recovery purposes.&lt;/P&gt;

&lt;P&gt;EDIT: Oh and a final consideration, if you are indexing events from local log files then you also have to consider that the original data will also remain - depending on the retention/rolling policies already in place&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2013 10:19:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90618#M3306</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-17T10:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90619#M3307</link>
      <description>&lt;P&gt;"The chances of the same question being posted by multiple people seems pretty unlikely and given how often this happens - why post under many usernames?"&lt;/P&gt;

&lt;P&gt;Maybe the person thought they stood a better chance of receive support by posting it more than once?.......? I don't know, it's a thought. &lt;/P&gt;

&lt;P&gt;So, I read the link you gave and I'm sorry...I'm still overwhelmed with trying to find my data and where it's located. I hope this user was helped, as for me...I'm still  wondering where the data went. Thanks anyway.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 18:42:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90619#M3307</guid>
      <dc:creator>marg224</dc:creator>
      <dc:date>2013-08-06T18:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90620#M3308</link>
      <description>&lt;P&gt;Data is stored in &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk&lt;/CODE&gt;, one directory per index (&lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; being where Splunk was installed). The files in the respective directories hold the data in the indexes. The data in these files is not meant to be read directly - it would be very much like trying to read MySQL's database files directly expecting to be able to make sense of them.&lt;/P&gt;

&lt;P&gt;EDIT: Upon reading the link, this is already explained there. Where is it you get confused? What are you trying to do and why?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 18:57:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90620#M3308</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-08-06T18:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90621#M3309</link>
      <description>&lt;P&gt;Ironically, this post relates to my question. I have a intermediate server with a heavy forwarder installed. I am using db connect app on the intermediate server to get mssql db logs. I want to forward them to an indexer. What path in the inputs.conf file should i monitor on the heavy forwarder? "/var/splunkhot/splunk/var/lib/splunk"?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2014 21:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90621#M3309</guid>
      <dc:creator>gurinderbhatti</dc:creator>
      <dc:date>2014-09-10T21:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90622#M3310</link>
      <description>&lt;P&gt;gurinderbhatti: I suggest you post that as a new question, with some additional detail about your deployment and usage of DB Connect.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2014 21:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90622#M3310</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2014-09-10T21:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90623#M3311</link>
      <description>&lt;P&gt;So that data is just stored in text files directly on the Splunk servers?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 18:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/90623#M3311</guid>
      <dc:creator>pbarbuto</dc:creator>
      <dc:date>2017-03-10T18:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Where is my data get stored in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/617590#M26236</link>
      <description>&lt;P&gt;Can we get this updated? I cannot find anywhere in the current Splunk docs that say where the files are&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 20:43:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Where-is-my-data-get-stored-in-Splunk/m-p/617590#M26236</guid>
      <dc:creator>gerryha</dc:creator>
      <dc:date>2022-10-18T20:43:00Z</dc:date>
    </item>
  </channel>
</rss>

