Splunk® Enterprise

Admin Manual

Download manual as PDF

Download topic as PDF

Splunk Enterprise default dashboards

Splunk Enterprise comes packaged with a set of useful dashboards. They help you to troubleshoot your system and searches and can also help you come up with ideas about how you might want to design dashboards and views of your own.

Activity dashboards

You can find the following dashboards by clicking Activity > System Activity in the user bar near the top of the page.

Note: These dashboards are visible only to users with Admin role permissions. See "Add and manage users" in Securing Splunk Enterprise. For information about setting up permissions for dashboards, see the Knowledge Manager manual.

ActivityDashboard.png

  • Search activity - This dashboard collection provides at-a-glance info about search activity for your Splunk instance. You can find out when searches are running, the amount of load they're putting on the system, which searches are the most popular, which search views and dashboards are getting the most usage, and more. The following dashboards are provided:
    • Search activity overview
    • Search details
    • Search user activity
  • Server activity - This collection of dashboards provides metrics related to splunkd and Splunk Web performance and is handy for troubleshooting. You'll find the numbers of errors reported, lists of the most recent errors, lists of timestamping issues and unhandled exceptions, a chart displaying recent browser usage, and more. The following dashboards are provided:
    • Internal messages and errors
    • License usage
  • Scheduler activity - This collection of dashboards gives you insight into the work of the search scheduler, which ensures that both ad hoc and scheduled searches are run in a timely manner.
    • Scheduler activity overview
    • Scheduler activity by user or app
    • Scheduler activity by saved search
    • Scheduler errors

The Summary Dashboard

The Summary dashboard is the first thing you see as you enter the Search & Reporting app. It provides a search bar and time range picker which you can use to input and run your initial search.

When you add an input to Splunk, that input gets added relative to the app you're in. Some apps, like the *nix and Windows apps, write input data to a specific index (in the case of *nix and Windows, that is the os index). If you review the summary dashboard and you don't see data that you're certain is in Splunk, be sure that you're looking at the right index.

You may want to add the index that an app uses to the list of default indexes for the role you're using. For more information about roles, refer to this topic about roles in Securing Splunk.For more information about Summary Dashboards, see the Search Tutorial.

PREVIOUS
Admin tasks with Splunk Web
  NEXT
Customize Splunk Web messages

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.6.0, 6.6.1


Comments

Hello Vasanthmss and Dpraveen88,
You are right! You can get similar menu from Monitoring Console. I posted a question and comments. Pls refer below url.
https://answers.splunk.com/answers/481270/how-do-i-get-activity-system-activity.html

Smpark82
December 11, 2016

"You can find the following dashboards by clicking Activity > System Activity in the user bar near the top of the page."
When i worked with 6.4.1, 6.4.2 i didn't see any activity > Dashboard tab in splunk dashboard panel.
How to enable this? Could please check it once and post here process

Dpraveen88
August 30, 2016

I couldn't see the related views. How to enable this feature after 6.4.1.

Vasanthmss
August 30, 2016

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters