Getting Data In

Confused about the data

SLowry
New Member

I've enabled Forwarding & Receiving to accept input from the Universal Forwarder that I installed on my servers. Using Wireshark I know data is being sent to the Splunk server. I'm confused about the next steps in terms of indexing the data. Where is it being stored on my server? Do I need to add files on the server? How does the data get to them?

Thanks

0 Karma
1 Solution

Ayn
Legend

You add data inputs on the Universal Forwarders. The forwarders will read data from these inputs and forward that data to the main Splunk indexer. The indexer stores this data in its index, typically in $SPLUNK_HOME/var/lib/splunk, where $SPLUNK_HOME usually is /opt/splunk in *NIX installations and C:\Program Files\Splunk in Windows installations.

View solution in original post

Ayn
Legend

You add data inputs on the Universal Forwarders. The forwarders will read data from these inputs and forward that data to the main Splunk indexer. The indexer stores this data in its index, typically in $SPLUNK_HOME/var/lib/splunk, where $SPLUNK_HOME usually is /opt/splunk in *NIX installations and C:\Program Files\Splunk in Windows installations.

SLowry
New Member

Thanks. You got me moving in the right direction.

0 Karma

DaveSavage
Builder

Slowry - Ayn is right - post your q's re WI and Windows Mgmt as new q's - the tagging system works in your favour and you will be able to see 'related' if not similar q's people have had. The user experience on the App's release page makes for good reading at http://splunk-base.splunk.com/apps/22315/splunk-app-for-windows
Br, Dave

0 Karma

Ayn
Legend

That's a separate question regarding those specific apps - best idea would be to post that on its own and tag it correctly, so people with knowledge of those apps (I don't have that, sorry) can see and respond.

SLowry
New Member

OK, I see lots of data in the Main file. That's good.
I have Windows Intelligence & Windows Management Apps installed. How do I tell them to use the Main index? I see Indexes for WI, but they are empty, I don't think that's correct, but I don't know how to get the data to them.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...