there are index =os and index=_internal .
Index=os, where there all info about OS performance data of servers (host), also host =ip*
index=_internal, there contain these OS data, but internal hosts.
Which index should I use?
The _internal index contains events Splunk writes about itself. For data about your servers, use index=os.
View solution in original post