Splunk Enterprise

Is it possible or advised to add a custom log to the _internal index?

nnesje
Loves-to-Learn Lots

Is it possible, or advised, to add a custom log to the Splunk _internal index?  What are the formatting rules if a log is added to the default location?

 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Log files have no formatting rules.  You just need to define a sourcetype that can parse them.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could add those if needed, but you should think what logs are system logs and what are applications logs. Only 1st one should add to internal. A good examples are e.g. some complex TA logs like DB Connect, M365 etc. 

Shortly just write your logs into …./splunk/var/log/splunk directory and splunk automatically add those to _internal. You could check format from any logs already in that directory.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...