The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: SplunkAdministration: Indexing

Previous Topic: Persistent error related to max_results_raw_size  |   Next Topic: Is there Splunk for HP-UX


Posts 1–3 of 3

I'm new to Splunk and have a few questions.

Indexing....

How can I determine that Splunk is indexing?
How can I tell if it's caught up with my data or if it's not?

TIA John

- The easiest way to confirm that Splunk is indexing is if you see the event count incrementing on the 'main' dashboard
- Search your data over the last 15 minutes and verify that the most recent data is in line with the most recent data in the files you are monitoring

Thank you