Monitoring Splunk

how to have splunk read its own logs?


Is it possible to have splunk display its own splunk server logs on the dashboard? (logins, data additions, starts stops) I have been looking for a way to do this and I am unable to find anything of the sort. has anyone done this themselves or seen something relating to it?

Tags (1)
0 Karma


Hi zblum,

check out indexes _internal, _audit, and _introspection to get all the Splunk events.

See also the docs .
You can also use the Splunk monitoring console to see a lot of reports and dashboards using these events.

Hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...