Getting Data In

Log checking

sushmitha_mj
Communicator

What command should I use to check spluk logs in a linux system?

And where should I run this command?

Tags (3)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

In Splunk : search for "index=_internal" - This will give you all internal Splunk logs on your instance(s).

Alternatively, and old school, you can look in the $splunk_home$|/opt/splunk/var/log/splunk/ folder and grep through the logs.

0 Karma

vincenteous
Communicator

This "logs" you're talking about, are they the one to check the state and errors in your Splunk instance? Or are they something else?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...