Getting Data In

After indexing logs in Splunk, where can I find the specific path where it is stored?

nishwanth
Engager

I have a server which transfers logs to the Splunk server, but I don't know where it is stored in Splunk. Can someone guide me how to find it?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If the answer solves your issue, do mark it as accepted. If not, do elaborate with more information about your issue.

0 Karma

jkat54
SplunkTrust
SplunkTrust

The files are stored in an index under SPLUNK_HOME/var/lib/splunk/[indexName]

But they are not human readable, they're stored in a proprietary format.

To find them "inside of Splunk" you need to open search and type "index=IndexName" where indexName is the index you put them into when you added the data (inputs.conf) usually has this specified.

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...