Monitoring Splunk

Splunk 6 splunkd messages in search


Hi I've just deployed Splunk 6 via the Chef cookbook on-line and I'm noticing some differences from Splunk 5. There are a LOT of "sourcetype=splunkd" messages in my general searches in a custom index I created (index=staging). Also, Splunk 6 is not allowing me to just search a sourcetype I have to first put in the index. My query "sourcetype=access_custom" is returning 0 results, but "index=staging sourcetype=access_custom" works.

My questions is, how to change this behaviors and is this something new and expected in Splunk 6 or is the configuration incorrect (maybe Chef cookbook)? I've set up many Splunk 5 architectures with lots of searches and dashboards etc. and have never seen either of these two.


Tags (3)
0 Karma


In order to make your searches work without using a specific index you will have to change your permissions for the role you are assigned to. Just add all non internal indexes to the list of indexes searched by default.

0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...