Index
The first and most basic search command that you can execute is to specify an index. Unless you are looking for events containing a particular text string and you have no idea what index or sourcetype those events might be found in, you should always specify an index at the beginning of your search string to avoid searching the entire set of indexes, which is terribly wasteful.
Splunk has internal indexes, such as _internal, _introspection, and _audit, that contain events from the internal, which are kept in $SPLUNK_HOME/var/log /introspection and $SPLUNK_HOME/var/log/splunk. By default, you must have admin privileges to view the events in these indexes.
Then there are the custom indexes that are created by various Splunk apps and the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access