Monitoring Splunk

Component Code List and Definitions

verizonrap2017
Loves-to-Learn

Does anyone know of a list of component codes and their meanings for at least _internal and _audit? I have asked instructors and Splunk direct with no help so far. 

Labels (1)
0 Karma

kiran_panchavat
Contributor

@verizonrap2017 

I'm not sure what you're looking for; are you looking for Splunk components or the default indexes in Splunk? Please use the links provided below for reference. 

https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Aboutmanagingindexes  

https://docs.splunk.com/Documentation/Splunk/9.2.1/Capacity/ComponentsofaSplunkEnterprisedeployment  

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.

0 Karma

verizonrap2017
Loves-to-Learn

Thank you Kiran. What I am looking for is the meaning of each component code found. For instance If I run - 

index=_*
| stats count by component index log_level

I see many component codes with Warning or Error. The question becomes what does that component code mean and if there is a warning or error what is the action needed to correct or tune? I do not see any documentation in Splunk to that effect and have asked Splunk PS, Splunk Instructors and Splunk Support. No answer yet.

I want to build dashboards and associated alerts to help me know the stability and status of the platform.

Thank you!

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...