Splunk Search

Does Splunk backup and archive Windows logs on a standalone Windows computer?

codymoore
New Member

After installing the free version of Splunk on a standalone Windows 7 PC and configuring Splunk to monitor the windows logs, does Splunk backup and archive the Windows logs (System, Security, and Application) to another folder on the harddrive? I can't really find any questions/answers as to how Splunk handles the Windows logs. Or is this something that has to be done manually, or can Splunk be setup/configured to do this after monitoring is setup?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Splunk wont backup the files but rather index them and retain them in Splunk for a default of 6 years or 500GB, whichever comes first. The index files are roughly 35 - 50% of the original file size depending on how many unique terms are in the logs. The data is stored under C:\Program Files\Splunk\var\lib\splunk\<INDEX-NAME>\db

http://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/HowSplunkstoresindexes

Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...