SPLK-2002(205Q) · Question #85
When Splunk is installed, where are the internal indexes stored by default?
The correct answer is B. SPLUNK_HOME/var/lib. Splunk internal indexes are the indexes that store Splunk's own data, such as internal logs, metrics, audit events, and configuration snapshots. By default, Splunk internal indexes are stored in the SPLUNK_HOME/var/lib/splunk directory, along with other user-defined indexes…
Question
When Splunk is installed, where are the internal indexes stored by default?
Options
- ASPLUNK_HOME/bin
- BSPLUNK_HOME/var/lib
- CSPLUNK_HOME/var/run
- DSPLUNK_HOME/etc/system/default
How the community answered
(51 responses)- B94% (48)
- C2% (1)
- D4% (2)
Explanation
Splunk internal indexes are the indexes that store Splunk's own data, such as internal logs, metrics, audit events, and configuration snapshots. By default, Splunk internal indexes are stored in the SPLUNK_HOME/var/lib/splunk directory, along with other user-defined indexes. The SPLUNK_HOME/bin directory contains the Splunk executable files and scripts. The SPLUNK_HOME/var/run directory contains the Splunk process ID files and lock files. The SPLUNK_HOME/etc/system/default directory contains the default Splunk configuration files.
Topics
Community Discussion
No community discussion yet for this question.