Hi there.
Splunk Linux version. On which directory are the logs, that come from another server through UDP, or from the same server, saved?
Thanks!
The logs are saved in Splunk's index, or "database" if you will. File system-wise, an index is distributed across a number of files, by default in $SPLUNK_HOME/var/lib
. These files are in a proprietary format that cannot (easily) be used for reading directly.
More information on Splunk indexes: http://docs.splunk.com/Documentation/Splunk/latest/admin/WhatsaSplunkindex
By default, Splunk will save it's data in the default 'main' index, which normally is located in the /opt/splunk/var/lib/defaultdb directory structure.
/k