Getting Data In

How to find which Data Source an event is originating from

mninansplunk
Path Finder

Hello,

I'm having a hard time trying to find what data source events from a search are originating from, the Search is:

source="/var/www/html/PIM/var/log/webservices/*"

I've looked thru the "Files % Directories" (Which I thought I would find it in there) and the rest of the Data Inputs, but can't seem to locate it anywhere.

A side question 🙂  I tried creating a new Files % Directories Data Input by putting the full Linux path like below:

//HostName/var/www/html/PIM/var/log/webservices/*

But It says Path can't be empty.  I'm sure this is probably not how you format a Linux path, just couldn't find what I'm doing wrong.

Thanks for any help at all,

Newb

 

 

 

Labels (2)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hi @mninansplunk   

  • If you're not sure which index contains your data, start with this search:
 

 

| tstats count where source="/var/www/html/PIM/var/log/webservices/*" by sourcetype index host



 

This is a fast way to find which indexes contain your data and see the associated hosts and sourcetypes.

  • Once you know the right index, you can do a more detailed search:
 

 

index=<your_index> source="/var/www/html/PIM/var/log/webservices/*" | stats count by source sourcetype host

 

 

For Files & Directories input - was it a typo there? single forward slashes like this?

 

 

/HostName/var/www/html/PIM/var/log/webservices/* 

 

make sure file permissions on your input directory and your Splunk forwarder has access to the path

Refer: https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/GetthetutorialdataintoSplunk
https://docs.splunk.com/Documentation/SplunkCloud/latest/Search/GetstartedwithSearch
https://www.splunk.com/en_us/blog/customers/splunk-clara-fication-search-best-practices.html


If this helps, Please UpVote.

 
If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...