Hello, I have a server indexer that crashes from time to time, what is the best way to investigate what caused the problem?
How can I see the logs through index=_internal and splunkd.log?
there is crash logs on the server in $SPLUNK_HOME/var/log/splunk/crash*.log it gets ingested under sourcetype=splunkd_crash_log