Getting Data In

Log checking

Communicator

What command should I use to check spluk logs in a linux system?

And where should I run this command?

Tags (3)
0 Karma

Splunk Employee
Splunk Employee

In Splunk : search for "index=_internal" - This will give you all internal Splunk logs on your instance(s).

Alternatively, and old school, you can look in the $splunk_home$|/opt/splunk/var/log/splunk/ folder and grep through the logs.

0 Karma

Communicator

This "logs" you're talking about, are they the one to check the state and errors in your Splunk instance? Or are they something else?

0 Karma