Find log files

To locate Splunk App for SOAR log files to help you troubleshoot issues, navigate to these locations:

  • Server configurations: $SPLUNK_HOME/var/log/splunk/soar_configuration.log.
  • Audit checkpoint: $SPLUNK_HOME/var/lib/splunk/modinputs/audit.
  • Audit logs: $SPLUNK_HOME/var/log/splunk/soar_audit.log.
  • Index creation and setup: $SPLUNK_HOME/var/log/splunk/soar_setup.log.