How can I look at indexing process? Can I see what splunk is indexing file by file. Because it looks like black box, I show source and then search index but don't understand how splunk will index new files.
you have some options. If you want to know which files splunk processes, you can for example take a look at the Trailing processor:
To check the performance of the indexing queues you can use the distributed management console. In the splunk webui go to settings > distributed management console > indexing performance.
To get a better understanding of the indexing process, take a look at the docs. For example here: Link