Splunk Enterprise

Indexed data

AliMaher
Path Finder

Hi,

I want to ask where i can find the indexed data stored as per the below, i found the bucket consist of the RAW data, index file and some meta data :

2024-06-17_024236.png

Labels (2)
0 Karma

glc_slash_it
Path Finder

Check this path in Indexer's filesystem:

 

/opt/splunk/var/lib/splunk/<any_index>/db

 

0 Karma

deepakc
Builder

The index  data lives on the Splunk indexer Server's . You typically  use a Splunk Universal Forwarder or Heavy forwarder or some other means to send data to the Indexers and they get stored into a bucket(folder). 

So login to your Splunk indexers and go to the storage volume and see the data there.  See the table  section "What the index directories look like" this will show you the paths 

https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/HowSplunkstoresindexes  

AliMaher
Path Finder

Great!

Thanks for your help, i had checked the article, but each bucket consist of raw data and tsidx file only.

i am asking after the raw data is parsed and normalized, should they stored in somewhere in the parsed form.

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...