Monitoring Splunk

Splunk 6 splunkd messages in search


Hi I've just deployed Splunk 6 via the Chef cookbook on-line and I'm noticing some differences from Splunk 5. There are a LOT of "sourcetype=splunkd" messages in my general searches in a custom index I created (index=staging). Also, Splunk 6 is not allowing me to just search a sourcetype I have to first put in the index. My query "sourcetype=access_custom" is returning 0 results, but "index=staging sourcetype=access_custom" works.

My questions is, how to change this behaviors and is this something new and expected in Splunk 6 or is the configuration incorrect (maybe Chef cookbook)? I've set up many Splunk 5 architectures with lots of searches and dashboards etc. and have never seen either of these two.


Tags (3)
0 Karma


In order to make your searches work without using a specific index you will have to change your permissions for the role you are assigned to. Just add all non internal indexes to the list of indexes searched by default.

0 Karma
Get Updates on the Splunk Community!

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...

Want to Reduce Costs, Mitigate Risk, Improve Performance, or Increase Efficiencies? ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...