<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where does splunk store the logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15784#M1813</link>
    <description>&lt;P&gt;we are in the process of investigating splunk for our IT datacenter. &lt;/P&gt;

&lt;P&gt;Does splunk store the old events that occured on a particular system. &lt;/P&gt;</description>
    <pubDate>Sat, 19 Jun 2010 00:40:09 GMT</pubDate>
    <dc:creator>mihika</dc:creator>
    <dc:date>2010-06-19T00:40:09Z</dc:date>
    <item>
      <title>Where does splunk store the logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15784#M1813</link>
      <description>&lt;P&gt;we are in the process of investigating splunk for our IT datacenter. &lt;/P&gt;

&lt;P&gt;Does splunk store the old events that occured on a particular system. &lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2010 00:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15784#M1813</guid>
      <dc:creator>mihika</dc:creator>
      <dc:date>2010-06-19T00:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15785#M1814</link>
      <description>&lt;P&gt;I'm not sure what you mean by "old logs"?  I'm guessing your question has to do with how splunk stores events in general.  There is also the discussion about event-retention policies which has to do with how long your events (or logs) are kept around after they have been indexed by splunk, but since your evaluating splunk, I'm guessing you aren't running to that just yet.&lt;/P&gt;

&lt;P&gt;Splunk stores all log as indexed events in a proprietary database-like "index" under your splunk install location.&lt;/P&gt;

&lt;P&gt;If your a looking for sizing information, it may be helpful to visit the directory where your data is stored.  Out of the box, splunk contains several indexes (sometimes called "databases").  Here is the location of your "main" (default) index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk/defaultdb
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The docs should give you a better idea of how this works.  I would start here:  &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/WhatsaSplunkindex" rel="nofollow"&gt;What's a Splunk index?&lt;/A&gt; and follow the various links provided.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2010 00:52:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15785#M1814</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-06-19T00:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15786#M1815</link>
      <description>&lt;P&gt;Please be more specific with your question and provide some context about what you are asking.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2010 11:28:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15786#M1815</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-06-19T11:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15787#M1816</link>
      <description>&lt;P&gt;If you are looking for logs for application errors (&lt;EM&gt;splunkd.log, python.log, etc.&lt;/EM&gt;),  you can find them here...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/var/log/splunk/
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 16 Feb 2013 13:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15787#M1816</guid>
      <dc:creator>slierninja</dc:creator>
      <dc:date>2013-02-16T13:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15788#M1817</link>
      <description>&lt;P&gt;Yes, Splunk will store the events that were monitored and send to him by forwarders, or syslog or scripts, or directly monitored etc...&lt;/P&gt;

&lt;P&gt;The events are stored in in the splunk indexers in indexes in a timestamp order.&lt;BR /&gt;
By default the retention size per index is 500GB and the time retention is 6 years. It can be changed of course depending of your needs and of your storage.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Feb 2013 22:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-logs/m-p/15788#M1817</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-02-16T22:36:58Z</dc:date>
    </item>
  </channel>
</rss>

