<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a guide or map to understand Splunk's internal indexes and their log content? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132269#M36068</link>
    <description>&lt;P&gt;Got it. There is some additional information in the topics that follow the one I previously linked, including some field information, but there isn't any comprehensive reference to the log files and fields in the documentation.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Nov 2014 18:51:31 GMT</pubDate>
    <dc:creator>ChrisG</dc:creator>
    <dc:date>2014-11-21T18:51:31Z</dc:date>
    <item>
      <title>Is there a guide or map to understand Splunk's internal indexes and their log content?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132266#M36065</link>
      <description>&lt;P&gt;Does there exist some sort of map or guide to understanding Splunk's internal indexes (_internal, _audit, _introspection)? Something like:&lt;BR /&gt;
&lt;CODE&gt;_internal&lt;BR /&gt;
   sourcetypes&lt;BR /&gt;
      splunkd&lt;BR /&gt;
         fields&lt;BR /&gt;
            per_user_thruput (description of value data)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I have found and been given a few great examples as well as hacked up some splunk on splunk dashboards, but I would like to know what logs contain what so that we can build some additional auditing reports.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132266#M36065</guid>
      <dc:creator>feickertmd</dc:creator>
      <dc:date>2020-09-28T18:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a guide or map to understand Splunk's internal indexes and their log content?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132267#M36066</link>
      <description>&lt;P&gt;There is a topic in the Troubleshooting Manual that provides a summary of &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Troubleshooting/WhatSplunklogsaboutitself"&gt;what Splunk Enterprise logs about itself&lt;/A&gt;, with links to more detailed information when it is available. Is that the material you are looking for?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 18:38:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132267#M36066</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2014-11-21T18:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a guide or map to understand Splunk's internal indexes and their log content?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132268#M36067</link>
      <description>&lt;P&gt;Close, but no cigar. It does tell me what logs it covers, but very little about what those logs contain or what their fields represent.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 18:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132268#M36067</guid>
      <dc:creator>feickertmd</dc:creator>
      <dc:date>2014-11-21T18:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a guide or map to understand Splunk's internal indexes and their log content?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132269#M36068</link>
      <description>&lt;P&gt;Got it. There is some additional information in the topics that follow the one I previously linked, including some field information, but there isn't any comprehensive reference to the log files and fields in the documentation.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 18:51:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132269#M36068</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2014-11-21T18:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a guide or map to understand Splunk's internal indexes and their log content?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132270#M36069</link>
      <description>&lt;P&gt;Actually, with version 6.0 some of what you want exists as sample data models included in the Search app. Go to Settings / Data Models, and choose the Search app and you'll see this:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/162i456D95365D5309F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 21:13:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132270#M36069</guid>
      <dc:creator>halr9000</dc:creator>
      <dc:date>2014-11-21T21:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a guide or map to understand Splunk's internal indexes and their log content?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132271#M36070</link>
      <description>&lt;P&gt;A thing of beauty!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2014 14:07:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-guide-or-map-to-understand-Splunk-s-internal-indexes/m-p/132271#M36070</guid>
      <dc:creator>feickertmd</dc:creator>
      <dc:date>2014-11-24T14:07:24Z</dc:date>
    </item>
  </channel>
</rss>

