Monitoring Splunk

Can't query index=_internal

sittipornbaycom
Observer

Hi

We can't search log index=_internal _audit _introspection
We setup role select indexes "All non-internal indexes" and "All internal indexes" but can't see log _internal

Thanks

Regards

Labels (1)
0 Karma

rkyadav
Path Finder

HI,
You can look into Authorize.conf for these -
srchIndexesDefault = _internal
srchIndexesAllowed= _internal

if still issue persist , You can look for something in splunkd.log that can help tell you where the problem is by using ERROR keyword.
CLI- grep ERROR $SPLUNK_HOME/var/log/splunk/splunkd.log

dave_null
Path Finder

What is your search query? Are you seeing anything when searching "index=_internal"?

0 Karma

sittipornbaycom
Observer

What is your search query?
index=_internal
Are you seeing anything when searching "index=_internal"?
I'm not see anything

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...