Monitoring Splunk

Can't query index=_internal

sittipornbaycom
Loves-to-Learn Lots

Hi

We can't search log index=_internal _audit _introspection
We setup role select indexes "All non-internal indexes" and "All internal indexes" but can't see log _internal

Thanks

Regards

Labels (1)
0 Karma

rkyadav
Path Finder

HI,
You can look into Authorize.conf for these -
srchIndexesDefault = _internal
srchIndexesAllowed= _internal

if still issue persist , You can look for something in splunkd.log that can help tell you where the problem is by using ERROR keyword.
CLI- grep ERROR $SPLUNK_HOME/var/log/splunk/splunkd.log

dave_null
Path Finder

What is your search query? Are you seeing anything when searching "index=_internal"?

0 Karma

sittipornbaycom
Loves-to-Learn Lots

What is your search query?
index=_internal
Are you seeing anything when searching "index=_internal"?
I'm not see anything

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...