Monitoring Splunk

Component Code List and Definitions

verizonrap2017
Loves-to-Learn

Does anyone know of a list of component codes and their meanings for at least _internal and _audit? I have asked instructors and Splunk direct with no help so far. 

Labels (1)
0 Karma

kiran_panchavat
Contributor

@verizonrap2017 

I'm not sure what you're looking for; are you looking for Splunk components or the default indexes in Splunk? Please use the links provided below for reference. 

https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Aboutmanagingindexes  

https://docs.splunk.com/Documentation/Splunk/9.2.1/Capacity/ComponentsofaSplunkEnterprisedeployment  

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.

0 Karma

verizonrap2017
Loves-to-Learn

Thank you Kiran. What I am looking for is the meaning of each component code found. For instance If I run - 

index=_*
| stats count by component index log_level

I see many component codes with Warning or Error. The question becomes what does that component code mean and if there is a warning or error what is the action needed to correct or tune? I do not see any documentation in Splunk to that effect and have asked Splunk PS, Splunk Instructors and Splunk Support. No answer yet.

I want to build dashboards and associated alerts to help me know the stability and status of the platform.

Thank you!

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...