<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where is forwarded data stored in the indexer after getting indexed? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164929#M33456</link>
    <description>&lt;P&gt;Hi seema2502,&lt;/P&gt;

&lt;P&gt;check your &lt;CODE&gt;$SPLUNK_HOME/etc/splunk-launch.conf&lt;/CODE&gt; for the &lt;CODE&gt;$SPLUNK_DB&lt;/CODE&gt; setting.&lt;BR /&gt;
If unset, becomes &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk&lt;/CODE&gt; (unix) or &lt;CODE&gt;%SPLUNK_HOME%\var\lib\splunk&lt;/CODE&gt; (windows)&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Thu, 16 Oct 2014 07:48:36 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-10-16T07:48:36Z</dc:date>
    <item>
      <title>Where is forwarded data stored in the indexer after getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164928#M33455</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;Where are the forwarded logs being saved in the indexer after getting indexed?&lt;BR /&gt;
As i know this is very known issue but still i did not get my answer for it.&lt;/P&gt;

&lt;P&gt;in general, indexes.conf contain below details :-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Cold    $SPLUNK_HOME/var/lib/splunk/defaultdb/colddb/*
Hot             $SPLUNK_HOME/var/lib/splunk/defaultdb/db/*
Thawed  $SPLUNK_HOME/var/lib/splunk/defaultdb/thaweddb/*  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But as per my indexes.conf file i can able to see :-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;coldPath = $SPLUNK_DB/audit/colddb
homePath = $SPLUNK_DB/audit/db
thawedPath = $SPLUNK_DB/audit/thaweddb
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;so here is the confusion in the path, it should be $SPLUNK_HOME or $SPLUNK_DB ?&lt;/P&gt;

&lt;P&gt;if it is $SPLUNK_HOME then please find the below details cause $SPLUNK_HOME= /opt/product/splunk  :-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;bash-3.2$ pwd
/opt/product/splunk/var/lib/splunk
bash-3.2$ ls -lrt
total 44
drwx------ 5 XYZ XYZ 4096 Jul  2  2012 summarydb
drwx------ 5 XYZ XYZ 4096 Jul  2  2012 _internaldb
drwx------ 5 XYZ XYZ 4096 Jul  2  2012 historydb
drwx------ 2 XYZ XYZ 4096 Jul  2  2012 hashDb
drwx------ 5 XYZ XYZ 4096 Jul  2  2012 defaultdb
drwx------ 5 XYZ XYZ 4096 Jul  2  2012 blockSignature
drwx------ 2 XYZ XYZ 4096 Jul  2  2012 authDb
drwx------ 5 XYZ XYZ 4096 Jul  2  2012 audit
drwx--x--- 4 XYZ XYZ 4096 Jul  2  2012 appserver
drwx------ 2 XYZ XYZ 4096 Jul  2  2012 persistentstorage
drwx------ 7 XYZ XYZ 4096 Jul  3  2012 fishbucket
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and i am not able to see the forwarded logs over here. &lt;BR /&gt;
or if it is $SPLUNK_DB then where can i see the full path of it?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Seema&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164928#M33455</guid>
      <dc:creator>seema2502</dc:creator>
      <dc:date>2020-09-28T17:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Where is forwarded data stored in the indexer after getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164929#M33456</link>
      <description>&lt;P&gt;Hi seema2502,&lt;/P&gt;

&lt;P&gt;check your &lt;CODE&gt;$SPLUNK_HOME/etc/splunk-launch.conf&lt;/CODE&gt; for the &lt;CODE&gt;$SPLUNK_DB&lt;/CODE&gt; setting.&lt;BR /&gt;
If unset, becomes &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk&lt;/CODE&gt; (unix) or &lt;CODE&gt;%SPLUNK_HOME%\var\lib\splunk&lt;/CODE&gt; (windows)&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2014 07:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164929#M33456</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-10-16T07:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Where is forwarded data stored in the indexer after getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164930#M33457</link>
      <description>&lt;P&gt;Hi Mus,&lt;/P&gt;

&lt;P&gt;Thanks for the quick response. &lt;BR /&gt;
yes i am able to see my $SPLUNK_DB path inside $SPLUNK_HOME/etc/splunk-launch.conf.&lt;/P&gt;

&lt;P&gt;when i checked inside the path found the below details:-&lt;/P&gt;

&lt;P&gt;/apps/splunk/data/var/lib/splunk&lt;BR /&gt;
bash-3.2$ du -sh *&lt;BR /&gt;
3.1G    audit&lt;BR /&gt;
4.0K    authDb&lt;BR /&gt;
20K blockSignature&lt;BR /&gt;
416G    defaultdb&lt;BR /&gt;
27M fishbucket&lt;BR /&gt;
4.0K    hashDb&lt;BR /&gt;
20K historydb&lt;BR /&gt;
2.4G    _internaldb&lt;BR /&gt;
1.2M    persistentstorage&lt;BR /&gt;
20K repolite_idx&lt;BR /&gt;
20K summarydb&lt;BR /&gt;
29M summary_forwarders&lt;BR /&gt;
39M summary_hosts&lt;BR /&gt;
15M summary_indexers&lt;BR /&gt;
17M summary_pools&lt;BR /&gt;
116M    summary_sources&lt;BR /&gt;
29M summary_sourcetypes&lt;/P&gt;

&lt;P&gt;As defaultdb is having 416G size i went inside the defaultdb directory &lt;/P&gt;

&lt;P&gt;/apps/splunk/data/var/lib/splunk/defaultdb&lt;BR /&gt;
bash-3.2$ du -sh *&lt;BR /&gt;
4.0K    colddb&lt;BR /&gt;
416G    db&lt;BR /&gt;
4.0K    thaweddb&lt;/P&gt;

&lt;P&gt;As db is having 416G size i went inside the db directory &lt;BR /&gt;
/apps/splunk/data/var/lib/splunk/defaultdb/db&lt;/P&gt;

&lt;P&gt;can you please confirm, are these logs the same which are being indexed after getting forwarded from forwarder.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Seema&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164930#M33457</guid>
      <dc:creator>seema2502</dc:creator>
      <dc:date>2020-09-28T17:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Where is forwarded data stored in the indexer after getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164931#M33458</link>
      <description>&lt;P&gt;each directory within &lt;CODE&gt;/apps/splunk/data/var/lib/splunk&lt;/CODE&gt; represents an index, each file within &lt;CODE&gt;/apps/splunk/data/var/lib/splunk/defaultdb/db&lt;/CODE&gt; represents a bucket (your events or data) of your &lt;CODE&gt;index=main&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;see the docs for more details &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.4/Indexer/HowSplunkstoresindexes"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.4/Indexer/HowSplunkstoresindexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2014 08:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-forwarded-data-stored-in-the-indexer-after-getting/m-p/164931#M33458</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-10-16T08:39:10Z</dc:date>
    </item>
  </channel>
</rss>

