Getting Data In

Indexing process

Path Finder

Hi guys!

How can I look at indexing process? Can I see what splunk is indexing file by file. Because it looks like black box, I show source and then search index but don't understand how splunk will index new files.

Tags (1)
0 Karma


you have some options. If you want to know which files splunk processes, you can for example take a look at the Trailing processor:


To check the performance of the indexing queues you can use the distributed management console. In the splunk webui go to settings > distributed management console > indexing performance.

To get a better understanding of the indexing process, take a look at the docs. For example here: Link



0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!