Monitoring Splunk

How can I count No. of times splunk has been restarted?


I'm trying to create a dashboard that displays the data for splunk restart 
the current search I'm using is index="_audit"  
but this shows the no. of times I've logged in instead of the no. of times I've restarted

Labels (1)
0 Karma


You'll find restarts with this query

index=_internal sourcetype=splunkd "Splunkd starting"
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...