Dashboards & Visualizations

Monitor Indexing on Dashboard

indikaw
Explorer

Hi All,

I have few questions to ask if you can help me.
My Splunk server only has 3 default indexes which are internal, main and audit. I am trying to create a dashboard so I can monitor the indexing activity at a glass everyday morning.

I still can't get the right search string to do this. Can you please let me know how to search for the indexing? So I can put that search in to a dashbord panel. Also then I can set that up for every 24 hours and every morning I can load the dashbord and have an idea about indexing.

Second question is, as same as above how do I get the indexing errors on to a dashboard.

Your help is more that appreciated.

Thanks
Indika

Tags (3)
0 Karma

Drainy
Champion

Pretty wide question.

My first answer would be, use Splunk SoS to check the health and for problems of your indexes. Use the deployment monitor to monitor activity. In reality your indexes should be configured in such a way that you don't need to continually monitor your environment like this. If you do need to then you need to sit down and make sure everything is correctly configured and that your licence meets your needs.
If you really need to then just pull the searches out of the SoS app, they cover everything you need to know (why re-invent the wheel! 🙂 ). If you had anything more specific then just reply back with more detail.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...