Monitoring feeds updating results

After the kl_feed_for_splunk.py utility finishes processing, the following messages are logged:

The app logs are stored in source="/opt/splunk/var/log/splunk/kaspersky/kl_feed_for_splunk.log".

To view or export the logs, specify source="/opt/splunk/var/log/splunk/kaspersky/kl_feed_for_splunk.log" in the search field on the Search tab.

The log file size is limited to 100 MB to avoid overflow in user disk space.

The kl_feed_for_splunk.py utility logs are written to index "internal". The index size is limited by the settings of the Splunk Cloud instance.

Page top