Deployment Architecture

How can i check which all logs are being ingested in my clients splunk architecture?

New Member



i am new to splunk and TH 

I want to understand how can i check which all logs are being ingested in my clients splunk architecture 

Also , is there a way i can look at clients network architecture from splunk?

Thanks in Advance

Labels (1)
0 Karma

Splunk Employee
Splunk Employee

Hey @SonakshiRaiTH,

Try running the below query for a short time period. It'll help you identify all the logs that are coming to Splunk or getting monitored by Splunk.

index=_internal source=*.log
| stats count by source

You can check the monitoring console of the environment to have the overview of the Splunk architecture.

If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...

What’s New in Splunk Cloud Platform 9.1.2308?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2308! Analysts can ...