Deployment Architecture

How can i check which all logs are being ingested in my clients splunk architecture?

New Member



i am new to splunk and TH 

I want to understand how can i check which all logs are being ingested in my clients splunk architecture 

Also , is there a way i can look at clients network architecture from splunk?

Thanks in Advance

Labels (1)
0 Karma

Splunk Employee
Splunk Employee

Hey @SonakshiRaiTH,

Try running the below query for a short time period. It'll help you identify all the logs that are coming to Splunk or getting monitored by Splunk.

index=_internal source=*.log
| stats count by source

You can check the monitoring console of the environment to have the overview of the Splunk architecture.

If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...