Splunk Search

Where do searches get logged in Splunk?

newbietosplunk
Engager

When we make searches in Splunk, under which log file do these searches get logged?

Example: we need the original place the search below is logged.

/splunkhome/bin/splunk dispatch "*" -auth uname:passwd
1 Solution

lguinn2
Legend

Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.

Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of index=_audit; the other internal logs are in index=_internal

You probably want to take a look at the documentation: What Splunk software logs about itself
It has a good explanation of the logs and what is in each.

View solution in original post

lguinn2
Legend

Every search has its directory with its own search.log file in splunkhome/var/lib/dispatch/run
However, this exists only for the lifetime of the search, which is typically 10 minutes. It contains many details about how the search was run, how many events were retrieved and how much time was spent in each step.

Every search is also logged in audit.log. The easiest way to view the audit log is to use Splunk itself. The audit log is part of index=_audit; the other internal logs are in index=_internal

You probably want to take a look at the documentation: What Splunk software logs about itself
It has a good explanation of the logs and what is in each.

lguinn2
Legend

Oh - and don't forget the Search Job Inspector! Whenever you run a search, you can access the inspector from the UI. It shows a nice summary with graphics of what is contained in the search log. There is also documentation here: View search job properties

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...