Splunk Search

Is there a guide or map to understand Splunk's internal indexes and their log content?

feickertmd
Communicator

Does there exist some sort of map or guide to understanding Splunk's internal indexes (_internal, _audit, _introspection)? Something like:
_internal
sourcetypes
splunkd
fields
per_user_thruput (description of value data)

I have found and been given a few great examples as well as hacked up some splunk on splunk dashboards, but I would like to know what logs contain what so that we can build some additional auditing reports.

1 Solution

halr9000
Motivator

Actually, with version 6.0 some of what you want exists as sample data models included in the Search app. Go to Settings / Data Models, and choose the Search app and you'll see this:

alt text

View solution in original post

halr9000
Motivator

Actually, with version 6.0 some of what you want exists as sample data models included in the Search app. Go to Settings / Data Models, and choose the Search app and you'll see this:

alt text

feickertmd
Communicator

A thing of beauty!

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There is a topic in the Troubleshooting Manual that provides a summary of what Splunk Enterprise logs about itself, with links to more detailed information when it is available. Is that the material you are looking for?

ChrisG
Splunk Employee
Splunk Employee

Got it. There is some additional information in the topics that follow the one I previously linked, including some field information, but there isn't any comprehensive reference to the log files and fields in the documentation.

0 Karma

feickertmd
Communicator

Close, but no cigar. It does tell me what logs it covers, but very little about what those logs contain or what their fields represent.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...