Getting Data In

How to find which Data Source an event is originating from

mninansplunk
Path Finder

Hello,

I'm having a hard time trying to find what data source events from a search are originating from, the Search is:

source="/var/www/html/PIM/var/log/webservices/*"

I've looked thru the "Files % Directories" (Which I thought I would find it in there) and the rest of the Data Inputs, but can't seem to locate it anywhere.

A side question 🙂  I tried creating a new Files % Directories Data Input by putting the full Linux path like below:

//HostName/var/www/html/PIM/var/log/webservices/*

But It says Path can't be empty.  I'm sure this is probably not how you format a Linux path, just couldn't find what I'm doing wrong.

Thanks for any help at all,

Newb

 

 

 

Labels (3)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hi @mninansplunk   

  • If you're not sure which index contains your data, start with this search:
 

 

| tstats count where source="/var/www/html/PIM/var/log/webservices/*" by sourcetype index host



 

This is a fast way to find which indexes contain your data and see the associated hosts and sourcetypes.

  • Once you know the right index, you can do a more detailed search:
 

 

index=<your_index> source="/var/www/html/PIM/var/log/webservices/*" | stats count by source sourcetype host

 

 

For Files & Directories input - was it a typo there? single forward slashes like this?

 

 

/HostName/var/www/html/PIM/var/log/webservices/* 

 

make sure file permissions on your input directory and your Splunk forwarder has access to the path

Refer: https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/GetthetutorialdataintoSplunk
https://docs.splunk.com/Documentation/SplunkCloud/latest/Search/GetstartedwithSearch
https://www.splunk.com/en_us/blog/customers/splunk-clara-fication-search-best-practices.html


If this helps, Please UpVote.

 
0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...