<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where do searches get logged in Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236842#M70365</link>
    <description>&lt;P&gt;Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run&lt;BR /&gt;
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.&lt;/P&gt;

&lt;P&gt;Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of &lt;CODE&gt;index=_audit&lt;/CODE&gt;; the other internal logs are in &lt;CODE&gt;index=_internal&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;You probably want to take a look at the documentation: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Troubleshooting/WhatSplunklogsaboutitself"&gt;What Splunk software logs about itself&lt;/A&gt; &lt;BR /&gt;
It has a good explanation of the logs and what is in each.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2016 16:12:36 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2016-11-23T16:12:36Z</dc:date>
    <item>
      <title>Where do searches get logged in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236841#M70364</link>
      <description>&lt;P&gt;When we make searches in Splunk, under which log file do these searches get logged?&lt;/P&gt;

&lt;P&gt;Example: we need the original place the search below is logged.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/splunkhome/bin/splunk dispatch "*" -auth uname:passwd
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 23 Nov 2016 14:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236841#M70364</guid>
      <dc:creator>newbietosplunk</dc:creator>
      <dc:date>2016-11-23T14:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Where do searches get logged in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236842#M70365</link>
      <description>&lt;P&gt;Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run&lt;BR /&gt;
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.&lt;/P&gt;

&lt;P&gt;Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of &lt;CODE&gt;index=_audit&lt;/CODE&gt;; the other internal logs are in &lt;CODE&gt;index=_internal&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;You probably want to take a look at the documentation: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Troubleshooting/WhatSplunklogsaboutitself"&gt;What Splunk software logs about itself&lt;/A&gt; &lt;BR /&gt;
It has a good explanation of the logs and what is in each.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 16:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236842#M70365</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-11-23T16:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Where do searches get logged in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236843#M70366</link>
      <description>&lt;P&gt;Oh - and don't forget the Search Job Inspector! Whenever you run a search, you can access the inspector from the UI. It shows a nice summary with graphics of what is contained in the search log. There is also documentation here: &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.1/Search/ViewsearchjobpropertieswiththeJobInspector"&gt;View search job properties&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 07:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-do-searches-get-logged-in-Splunk/m-p/236843#M70366</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-11-30T07:00:06Z</dc:date>
    </item>
  </channel>
</rss>

