I'm troubleshooting a possible configuration change to splunk-launch.conf and wonder if there is a search I can run in Enterprise that will tell me what paths the Splunk index data was written to, preferably by index.
I would install the app Firebrigade. Great insight into your indexes.
Use dbinspect command. It will give you the breakdown of where the data is stored by bucket.
| dbinspect index=yourindex