Security

Why do I see no results when I run "index=_introspection host=hostname" search?

kotig
Path Finder

I am trying to get the data from the disk_objects.log file running the search: index=_introspection host=hostname but nothing is returned. Can someone help?

Is there anything that need to be done so that we can search on the _introspection index?
Is the _introspection index available for the Linux boxes as well?

Thanks
Koti

0 Karma

lguinn2
Legend

The _introspection index is only viewable by admins. It is available for any Splunk instance, regardless of OS.
If you don't see anything from your query, try a broader search like "index=_introspection" and check to see what hosts appear in the results. Perhaps your host name is wrong.

Many of the reports in the Monitoring Console (formerly the DMC) are based on the introspection data. Hopefully, you have set up the MC for your environment. You can see a lot of the disk usage information there as well.

0 Karma

kotig
Path Finder

Appreciate your help on responding to my question. But as I am pretty new to this, I am not clear on what does it mean by MC. I am not sure if that was done by our Admins. I am not sure if I am an admin. Is there any other way to find out the disk usage other than the introspection?

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...