I have just installed a copy of Splunk to test it for our company. I have 2 basic questions, appreciate if some one can take some time to answer those:
1. I understand that incoming data is indexed and raw data is compressed when it is into Splunk. Where is the actual raw data available ? Is that stored in a DB, text file or an XML file. Where can I see that file ?
2. I have added a data input and configured UDP port as source. Can different source types forward data to the same source ?
Thanks.
[Revised on Wed, 18 Nov 2009 06:45:07 -0800]
Also, when the indexes are exported is the data associated with those exported as well ?