Splunk Search

Where do searches get logged in Splunk?

newbietosplunk
Engager

When we make searches in Splunk, under which log file do these searches get logged?

Example: we need the original place the search below is logged.

/splunkhome/bin/splunk dispatch "*" -auth uname:passwd
1 Solution

lguinn2
Legend

Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.

Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of index=_audit; the other internal logs are in index=_internal

You probably want to take a look at the documentation: What Splunk software logs about itself
It has a good explanation of the logs and what is in each.

View solution in original post

lguinn2
Legend

Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.

Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of index=_audit; the other internal logs are in index=_internal

You probably want to take a look at the documentation: What Splunk software logs about itself
It has a good explanation of the logs and what is in each.

lguinn2
Legend

Oh - and don't forget the Search Job Inspector! Whenever you run a search, you can access the inspector from the UI. It shows a nice summary with graphics of what is contained in the search log. There is also documentation here: View search job properties

Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...