Where does logs stored


Hello Splunkers,

I have an enterprise splunk deployment with 4 indexer clisters and a Search Head cluster.

I have installed Sophos app on Search head. I am getting the logs from sophos central servers by api integration method. I would like to know where these logs are stored? How to identify which indexer its storing on.

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Look at the field splunk_server. This will tell you the hostname of the indexer that the data is stored on.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!