<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where does splunk store the notable events logs and how to know the retention period for the same? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344984#M63409</link>
    <description>&lt;P&gt;Hi faisal_saifi,&lt;BR /&gt;
you have many ways to have information (like retention period) about your indexes, you could use dbinspect CLI or enter in indexes.conf files or (easier) you can use the Distributed Monitoring Console.&lt;BR /&gt;
There is a specific dashboard (Index Details: instance) to show all details about every index (Data Age vs Frozen Age, Index Usage, Home Path Usage, Cold Path Usage, retention, buckets...)&lt;/P&gt;

&lt;P&gt;About the location of logs in Splunk, you can find it in the same DMC dashboard below or in $SPLUNK_DB$ or in the indexes page.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2017 08:13:18 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-03-10T08:13:18Z</dc:date>
    <item>
      <title>Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344982#M63407</link>
      <description>&lt;P&gt;Where does splunk store the notable events logs and how to know the retention period for the same?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 07:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344982#M63407</guid>
      <dc:creator>faisal_saifi</dc:creator>
      <dc:date>2017-03-10T07:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344983#M63408</link>
      <description>&lt;P&gt;Have you checked out dbinspect command? It gives info for various buckets in an index&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Dbinspect"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Dbinspect&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 07:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344983#M63408</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-03-10T07:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344984#M63409</link>
      <description>&lt;P&gt;Hi faisal_saifi,&lt;BR /&gt;
you have many ways to have information (like retention period) about your indexes, you could use dbinspect CLI or enter in indexes.conf files or (easier) you can use the Distributed Monitoring Console.&lt;BR /&gt;
There is a specific dashboard (Index Details: instance) to show all details about every index (Data Age vs Frozen Age, Index Usage, Home Path Usage, Cold Path Usage, retention, buckets...)&lt;/P&gt;

&lt;P&gt;About the location of logs in Splunk, you can find it in the same DMC dashboard below or in $SPLUNK_DB$ or in the indexes page.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 08:13:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344984#M63409</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-03-10T08:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344985#M63410</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;BR /&gt;
These are the indexes where collected logs stored. but i am unable to find the location where the data of notable events are getting stored. please let me know where these logs stored. whether it stored on search head itself or in any default index on indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 09:14:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344985#M63410</guid>
      <dc:creator>faisal_saifi</dc:creator>
      <dc:date>2017-03-10T09:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344986#M63411</link>
      <description>&lt;P&gt;Hi Niketnilay,&lt;BR /&gt;
These are the indexes where collected logs stored. but i am unable to find the location where the data of notable events are getting stored. please let me know where these logs stored. whether it stored on search head itself or in any default index on indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 09:15:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344986#M63411</guid>
      <dc:creator>faisal_saifi</dc:creator>
      <dc:date>2017-03-10T09:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344987#M63412</link>
      <description>&lt;P&gt;Hi faisal_saifi,&lt;BR /&gt;
Sorry but I don't understand what you mean with notable events:&lt;BR /&gt;
All Splunk Data are usually stored on the indexes and indexes are on the Indexers.&lt;BR /&gt;
Usually Search Heads logs are sent to indexers to have all logs on indexers.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 10:30:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344987#M63412</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-03-10T10:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344988#M63413</link>
      <description>&lt;P&gt;Are you referring to notable events generated by the Splunk App for Enterprise Security, or for those from the Splunk App for IT Service Service Intelligence (ITSI)? Please clarify.&lt;/P&gt;

&lt;P&gt;If it is neither, please describe what you mean by "notable events".&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 19:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344988#M63413</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-03-10T19:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344989#M63414</link>
      <description>&lt;P&gt;Hi Niketnilay,&lt;BR /&gt;
Yes you are absolutely right. I am talking about the notable events generated by the Splunk App for Enterprise Security based on the correlation rules created.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 01:30:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344989#M63414</guid>
      <dc:creator>faisal_saifi</dc:creator>
      <dc:date>2017-03-13T01:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344990#M63415</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;BR /&gt;
I am talking about the notable events generated by the Splunk App for Enterprise Security based on the correlation rules created. Once the rules gets triggered, a notable event(Alert) generated in Enterprise Security App.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 01:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344990#M63415</guid>
      <dc:creator>faisal_saifi</dc:creator>
      <dc:date>2017-03-13T01:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344991#M63416</link>
      <description>&lt;P&gt;Ah, this was the misunderstanding!&lt;BR /&gt;
I think that Notable events are alerts stored in savedsearches.conf file in ES App, but i'm not an expert in ES.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 07:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344991#M63416</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-03-13T07:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Where does splunk store the notable events logs and how to know the retention period for the same?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344992#M63417</link>
      <description>&lt;P&gt;This may help: &lt;A href="http://dev.splunk.com/view/enterprise-security/SP-CAAAFBA"&gt;Notable Index&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 16:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-does-splunk-store-the-notable-events-logs-and-how-to-know/m-p/344992#M63417</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-03-13T16:49:03Z</dc:date>
    </item>
  </channel>
</rss>

