Dashboards & Visualizations

Monitor Indexing on Dashboard

indikaw
Explorer

Hi All,

I have few questions to ask if you can help me.
My Splunk server only has 3 default indexes which are internal, main and audit. I am trying to create a dashboard so I can monitor the indexing activity at a glass everyday morning.

I still can't get the right search string to do this. Can you please let me know how to search for the indexing? So I can put that search in to a dashbord panel. Also then I can set that up for every 24 hours and every morning I can load the dashbord and have an idea about indexing.

Second question is, as same as above how do I get the indexing errors on to a dashboard.

Your help is more that appreciated.

Thanks
Indika

Tags (3)
0 Karma

Drainy
Champion

Pretty wide question.

My first answer would be, use Splunk SoS to check the health and for problems of your indexes. Use the deployment monitor to monitor activity. In reality your indexes should be configured in such a way that you don't need to continually monitor your environment like this. If you do need to then you need to sit down and make sure everything is correctly configured and that your licence meets your needs.
If you really need to then just pull the searches out of the SoS app, they cover everything you need to know (why re-invent the wheel! 🙂 ). If you had anything more specific then just reply back with more detail.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...