Splunk Search

Upgraded to 5.x, now my _internal search doesn't work - what changed?

mctester
Communicator

On 4.3.2 I used to able to run this search to check input modules loaded..

index=_internal source=*splunkd.log splunklogger "*/input/* loaded"  | dedup message

Seems it doesn’t work on 5.X?

0 Karma

rroberts
Splunk Employee
Splunk Employee

Looks like now its under loader not splunklogger and ya gotta go look at composite.xml for details.

02-13-2013 16:35:06.875 -0500 INFO loader - loading modules from /home/stua/opt/splunk/etc/modules

02-13-2013 16:35:06.877 -0500 INFO loader - Writing out composite configuration file: /home/stua/opt/splunk/var/run/splunk/composite.xml

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...