Splunk Search

Where do searches get logged in Splunk?

newbietosplunk
Engager

When we make searches in Splunk, under which log file do these searches get logged?

Example: we need the original place the search below is logged.

/splunkhome/bin/splunk dispatch "*" -auth uname:passwd
1 Solution

lguinn2
Legend

Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.

Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of index=_audit; the other internal logs are in index=_internal

You probably want to take a look at the documentation: What Splunk software logs about itself
It has a good explanation of the logs and what is in each.

View solution in original post

lguinn2
Legend

Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.

Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of index=_audit; the other internal logs are in index=_internal

You probably want to take a look at the documentation: What Splunk software logs about itself
It has a good explanation of the logs and what is in each.

lguinn2
Legend

Oh - and don't forget the Search Job Inspector! Whenever you run a search, you can access the inspector from the UI. It shows a nice summary with graphics of what is contained in the search log. There is also documentation here: View search job properties

Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...