I'm trying to create a dashboard that displays the data for splunk restart the current search I'm using is index="_audit" but this shows the no. of times I've logged in instead of the no. of times I've restarted
You'll find restarts with this query
index=_internal sourcetype=splunkd "Splunkd starting"