The splunk tsidx format is not really geared for direct examination but you can, as @aakwah explained. The other thing that you can do is run searches from the CLI, like this:
/opt/splunk/bin/splunk search "index=foo bar"
Also, you can check your syslog configuration to see where it is writing the incoming data (or your Splunk inputs.conf ) and do a tail -f <filename> on those files to see the data coming in. You can also use tcpdump to snoop the incoming port to grab it before/as it comes into syslog.
... View more