Getting Data In

Describtion of _internal index fields - /opt/splunk/var/log/splunk/license_usage.log

mbschriek
Explorer

Is there some documentation including the definition and description of fields in the _internal index.

For example:
- /opt/splunk/var/log/splunk/license_usage.log

field;
- h
- i
- idx
- s
- st

Kind regards,

Tags (1)
1 Solution

javiergn
Super Champion

I don't think so but in your particular case:

  • h -> host
  • i -> license slave instance (you can find them here: | rest splunk_server=local /services/licenser/slaves)
  • idx -> index
  • s -> source
  • st -> sourcetype

In general you can either guess what the fields are or simply look for existing Splunk searches and how they are used to find what you are looking.

Maybe the following links can help too:

https://answers.splunk.com/answers/194456/is-there-a-guide-or-map-to-understand-splunks-inte.html
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself

Regards,
J

View solution in original post

javiergn
Super Champion

I don't think so but in your particular case:

  • h -> host
  • i -> license slave instance (you can find them here: | rest splunk_server=local /services/licenser/slaves)
  • idx -> index
  • s -> source
  • st -> sourcetype

In general you can either guess what the fields are or simply look for existing Splunk searches and how they are used to find what you are looking.

Maybe the following links can help too:

https://answers.splunk.com/answers/194456/is-there-a-guide-or-map-to-understand-splunks-inte.html
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself

Regards,
J

mbschriek
Explorer

Thanks for the reply. I guessed the same field descriptions, still it's strange that there is no elaborated documentation about these inputs.

Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...