I getting indications that Splunk Ent. / ES was restarted. Is it possible to find when & by whom? Thank u very much for your response.
Hello @SamHTexas ,
To see who restarted Splunk, please run the search
index=_internal sourcetype=splunkd "Received shutdown signal." | ...rest of your query with required fields...
Hope this helps,
*** If this helped, please accept it as a solution. It helps others to find the solution more quickly ***