Getting Data In

Organizing Logs

NeoJim
New Member

I'm new and a novice to Splunk although i have installed, setup and played with searches in Splunk in a lab.
My question is if I have servers that are sending logs all from different “environments” (prod, test, dev) what is the best way to organize the logs coming in by environment. I see I can use tags and/or indexes, but which way would make more sense.

Labels (1)
0 Karma

SinghK
Builder

Data retention and access and how sensitive is the data will determine how you will classify and store it. Different approaches for diff organisations. Few of the methods have already been listed by @inventsekar and @isoutamo .

0 Karma

inventsekar
SplunkTrust
SplunkTrust

>>> I'm new and a novice to Splunk although i have installed, setup and played with searches in Splunk in a lab.

all the best for your splunk journey!


>>> My question is if I have servers that are sending logs all from different “environments” (prod, test, dev) what is the best way to organize the logs coming in by environment.

Generally we will use index/host/source/sourcetype combinations to identify/group log events

(in bigger environments you will automatically have separate dev / test / prod environments)


>>> I see I can use tags and/or indexes, but which way would make more sense.

Yes, tags are a good way to group logs. more opt way would be source/sourcetype. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You should figure out if there are some regulations which put some requirements for you (e..g separate dev/test and prod access/data). Then there could be some restrictions from your company side which define how to handle data and access to it.

Then in splunk point of view you should thing how long you want/need to store data (clarify it based on that).  Another option is who can access it. This one is the cardinality and amount of ingested data. These are good starting point to divide event to separate indexes. Over that you should/could also use tags, event types etc. to manage events more easily.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...