I'm trying to create a dashboard that displays the data for splunk restart
the current search I'm using is index="_audit"
but this shows the no. of times I've logged in instead of the no. of times I've restarted
You'll find restarts with this query
index=_internal sourcetype=splunkd "Splunkd starting"