When Splunk is installed, where are the internal indexes stored by default?
When Splunk is installed, where are the internal indexes stored by default?
When Splunk is installed, internal indexes are stored by default in the directory SPLUNK_HOME/var/lib. This directory holds various data including the indexed logs and other vital internal information necessary for Splunk's operation.
by default: SPLUNK_HOME/var/lib
B is correct
Cluster Administration PDF - Page 34: Bucket location defined as homePath, coldPath, & thawedPath of index: • Default: $SPLUNK_HOME/var/lib/splunk/<indexname>/*
page 101 troubleshooting
B. SPLUNK_HOME/var/lib