Monitoring Splunk

how to have splunk read its own logs?

zblum
Engager

Is it possible to have splunk display its own splunk server logs on the dashboard? (logins, data additions, starts stops) I have been looking for a way to do this and I am unable to find anything of the sort. has anyone done this themselves or seen something relating to it?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi zblum,

check out indexes _internal, _audit, and _introspection to get all the Splunk events.

See also the docs http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself .
You can also use the Splunk monitoring console http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview to see a lot of reports and dashboards using these events.

Hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...