Deployment Architecture

Where does logs stored

aruncp333
Explorer

Hello Splunkers,

I have an enterprise splunk deployment with 4 indexer clisters and a Search Head cluster.

I have installed Sophos app on Search head. I am getting the logs from sophos central servers by api integration method. I would like to know where these logs are stored? How to identify which indexer its storing on.

Tags (1)
0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Look at the field splunk_server. This will tell you the hostname of the indexer that the data is stored on.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...