Monitoring Splunk

how to have splunk read its own logs?

zblum
Engager

Is it possible to have splunk display its own splunk server logs on the dashboard? (logins, data additions, starts stops) I have been looking for a way to do this and I am unable to find anything of the sort. has anyone done this themselves or seen something relating to it?

Tags (1)
0 Karma

MuS
Legend

Hi zblum,

check out indexes _internal, _audit, and _introspection to get all the Splunk events.

See also the docs http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself .
You can also use the Splunk monitoring console http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview to see a lot of reports and dashboards using these events.

Hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...