Getting Data In

Indexing process

dimoobraznii
Path Finder

Hi guys!

How can I look at indexing process? Can I see what splunk is indexing file by file. Because it looks like black box, I show source and then search index but don't understand how splunk will index new files.

Tags (1)
0 Karma

tom_frotscher
Builder

Hi,
you have some options. If you want to know which files splunk processes, you can for example take a look at the Trailing processor:

https://localhost:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus

To check the performance of the indexing queues you can use the distributed management console. In the splunk webui go to settings > distributed management console > indexing performance.

To get a better understanding of the indexing process, take a look at the docs. For example here: Link

Greetings

Tom

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...