Monitoring Splunk

how do I generate a diag (Splunk diagnostics file)?

benstraw
Splunk Employee
Splunk Employee

How do I generate a diag (Splunk diagnostic) file for splunk support?

Labels (1)
Tags (3)
1 Solution

jrodman
Splunk Employee
Splunk Employee

Run the command:

splunk diag

a splunk-diag.tar.gz file should be generated in your $SPLUNK_HOME dir.

View solution in original post

jrodman
Splunk Employee
Splunk Employee

Run the command:

splunk diag

a splunk-diag.tar.gz file should be generated in your $SPLUNK_HOME dir.

Simeon
Splunk Employee
Splunk Employee

You can get additional options, such as excluding files, by running the help command:

./splunk diag -help help

0 Karma

jrodman
Splunk Employee
Splunk Employee

This changed a bit at some point to need only ./splunk diag --help or splunk help diag

0 Karma

jrodman
Splunk Employee
Splunk Employee

Heh, note I just changed this so it will be called something like diag-splunkserver-2010-4-5.tar.gz. Coming in 4.1.1 or .2 or so.

And again for 6.2.x soon it will include the time of day upon QA & support request.

0 Karma

jdomin30
New Member

How can I email and share the diag with another team? What would be the required steps that I have to take through CLI?

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...