Splunk Enterprise Security

Splunk Component Reboot/Restart Detected

sunitm
New Member

Hi,

Is there a way to notify if any splunk components were restarted. For Example-Deployment servers, Search heads etc.. were restarted and an user needs to be notified. Thanks in advance.

Regards,
Sunith

0 Karma
1 Solution

ivanreis
Builder

If I understood you question properly, do you want to know when the splunk service(splunkd) is restarted? If so this information is under _audit log
run this query : index=_audit action=restart_splunkd

you can create an alert to be notified when this happen.

View solution in original post

0 Karma

sunitm
New Member

Hello Ivan,

Thanks for your prompt reply. Yes this answers my query.

0 Karma

ivanreis
Builder

If I understood you question properly, do you want to know when the splunk service(splunkd) is restarted? If so this information is under _audit log
run this query : index=_audit action=restart_splunkd

you can create an alert to be notified when this happen.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...