Where does splunk store the logs? (2024)

I'm not sure what you mean by "old logs"? I'm guessing your question has to do with how splunk stores events in general. There is also the discussion about event-retention policies which has to do with how long your events (or logs) are kept around after they have been indexed by splunk, but since your evaluating splunk, I'm guessing you aren't running to that just yet.

Splunk stores all log as indexed events in a proprietary database-like "index" under your splunk install location.

If your a looking for sizing information, it may be helpful to visit the directory where your data is stored. Out of the box, splunk contains several indexes (sometimes called "databases"). Here is the location of your "main" (default) index:

$SPLUNK_HOME/var/lib/splunk/defaultdb

The docs should give you a better idea of how this works. I would start here: What's a Splunk index? and follow the various links provided.

Where does splunk store the logs? (2024)
Top Articles
Latest Posts
Article information

Author: Allyn Kozey

Last Updated:

Views: 5456

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.