Splunk records its internal log data (ERROR, INFO, WARN, etc) in the following locations: $SPLUNK_HOME/var/log/splunk/ $SPLUNK_HOME/var/log/splunk/introspection/ In addition, each Splunk app or add-on may generate its own dedicated log file within the $SPLUNK_HOME/var/log/splunk/ directory. This makes it easier to understand and monitor activity specific to that app or add-on. If I were troubleshooting, I’d simply open the Search Head UI and run a query like: index=_* "<ERROR STRING>" This quickly surfaces any matching error messages across Splunk’s internal logs.
... View more