Monitoring Splunk

how to have splunk read its own logs?


Is it possible to have splunk display its own splunk server logs on the dashboard? (logins, data additions, starts stops) I have been looking for a way to do this and I am unable to find anything of the sort. has anyone done this themselves or seen something relating to it?

Tags (1)
0 Karma


Hi zblum,

check out indexes _internal, _audit, and _introspection to get all the Splunk events.

See also the docs .
You can also use the Splunk monitoring console to see a lot of reports and dashboards using these events.

Hope this helps ...

cheers, MuS

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!