Deployment Architecture

How can i check which all logs are being ingested in my clients splunk architecture?

SonakshiRaiTH
New Member

Hi 

 

i am new to splunk and TH 

I want to understand how can i check which all logs are being ingested in my clients splunk architecture 

Also , is there a way i can look at clients network architecture from splunk?

Thanks in Advance

Labels (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @SonakshiRaiTH,

Try running the below query for a short time period. It'll help you identify all the logs that are coming to Splunk or getting monitored by Splunk.

index=_internal source=*.log
| stats count by source

You can check the monitoring console of the environment to have the overview of the Splunk architecture.

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...