<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which index does search.log  data populates in, in splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295374#M93293</link>
    <description>&lt;P&gt;Search logs are not indexed so you won't find them in the UI, except via the job inspector.&lt;/P&gt;

&lt;P&gt;The disk quota is the amount of storage allowed for the search.  I believe it is in bytes.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Feb 2018 14:07:58 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2018-02-15T14:07:58Z</dc:date>
    <item>
      <title>Which index does search.log  data populates in, in splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295373#M93292</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;Does anyone know which index does search.log  data populates in?&lt;BR /&gt;
I find search.log during a job inspect, mostly its the source /var/run/ dispatch.&lt;BR /&gt;
How to fetch that in Splunk UI?&lt;/P&gt;

&lt;P&gt;Also another question,&lt;/P&gt;

&lt;P&gt;What does the line below represent? Does it report the size in MB?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;INFO  DispatchThread - Disk quota = 31457280000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Cheers !&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 13:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295373#M93292</guid>
      <dc:creator>Mohsin123</dc:creator>
      <dc:date>2018-02-15T13:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Which index does search.log  data populates in, in splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295374#M93293</link>
      <description>&lt;P&gt;Search logs are not indexed so you won't find them in the UI, except via the job inspector.&lt;/P&gt;

&lt;P&gt;The disk quota is the amount of storage allowed for the search.  I believe it is in bytes.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 14:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295374#M93293</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-02-15T14:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Which index does search.log  data populates in, in splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295375#M93294</link>
      <description>&lt;P&gt;are you just trying to get the search string, itself?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 14:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295375#M93294</guid>
      <dc:creator>iandrews_splunk</dc:creator>
      <dc:date>2018-02-15T14:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Which index does search.log  data populates in, in splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295376#M93295</link>
      <description>&lt;P&gt;search.log is not indexed, and it expires (gets deleted) when the job expires.&lt;/P&gt;

&lt;P&gt;Each user (or role) has a maximum disk quota fromwhich search jobs consume space (until they expire).&lt;BR /&gt;
Run too many large searches, and the quota fills up, preventing more searches, until some of the old ones have been cleared out (by default 10 mins).&lt;BR /&gt;
I expect that value to be in bytes, rather than MB.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 14:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Which-index-does-search-log-data-populates-in-in-splunk/m-p/295376#M93295</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-02-15T14:16:25Z</dc:date>
    </item>
  </channel>
</rss>

