Monitoring Splunk

Logging of Restart Trigger

TheEggi98
Path Finder

Hi there,

for better visibility i built a dashboard for indexer restarts, this dashboard is based on the _internal index and the /var/log/messages from the indexers themself.

I would like to add the Info how the restart was triggered.
so i can see whether the restart came from the manager (WebUI: Configuration Bundle Actions) or was done via the cli.
Does Splunk log this? If yes where do i find that info?

Thanks in advance!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...