Splunk Enterprise

Can someone give me an idea about fields under the index _introspection? How can we calculate run time of process from elapsed time and memory usage of each process?

vinillukes
Explorer

I am particularly interested in the fields data.elapsed and data.mem_used under introspection. Can we calculate runtime and memory usage from these values?

0 Karma

somesoni2
Revered Legend

You can use following links to know more about what is getting logged in index=_introspection.
http://docs.splunk.com/Documentation/Splunk/7.1.1/Troubleshooting/Whatdatagetslogged
http://docs.splunk.com/Documentation/Splunk/7.1.1/RESTREF/RESTintrospect#server.2Fstatus.2Fresource-...

Based on description on 2nd link, data.elapsed is the run time and mem.used is memory (physical) usage.

vinillukes
Explorer

Thank you. Can we check with the search_id from _introspection under _audit to find the corresponding events?

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...