Monitoring Splunk

Can't query index=_internal

sittipornbaycom
Loves-to-Learn Lots

Hi

We can't search log index=_internal _audit _introspection
We setup role select indexes "All non-internal indexes" and "All internal indexes" but can't see log _internal

Thanks

Regards

Labels (1)
0 Karma

rkyadav
Path Finder

HI,
You can look into Authorize.conf for these -
srchIndexesDefault = _internal
srchIndexesAllowed= _internal

if still issue persist , You can look for something in splunkd.log that can help tell you where the problem is by using ERROR keyword.
CLI- grep ERROR $SPLUNK_HOME/var/log/splunk/splunkd.log

dave_null
Path Finder

What is your search query? Are you seeing anything when searching "index=_internal"?

0 Karma

sittipornbaycom
Loves-to-Learn Lots

What is your search query?
index=_internal
Are you seeing anything when searching "index=_internal"?
I'm not see anything

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...