Manage and debug the local server in Splunk App for Infrastructure
Only admins with permission to view the _internal
index data can access this troubleshooting feature.
Manage server settings for SAI, including viewing internal server log data to better understand the environment when experiencing issues around data collection, performance issues, and so on. You can also restart your instance to reset server logging.
Investigate internal log data
- Go to Settings > Server settings.
- Under Server Logging, click the Investigate button. The Analysis Workspace displays with the _internal index log data.
- Select a log or logs to display in the workspace. A chart for each selected log displays.
- Actions you can perform:
- Hover your cursor over an area of the chart to display count and event time information.
- Click the expand view icon in the upper right of the chart to display detailed time and event information.
- Click the ellipsis icon to save a report, clone the panel, or export as a .png or .csv file.
- Use the Split by and Filters in the right panel to filter the log data in the chart.
Restart the server
- Go to Settings > Server settings.
- Click Restart Splunk.
- Confirm you want to restart Splunk. Click Restart.
SAI version 1.3.x is not compatible with the Splunk Add-on for Windows |
This documentation applies to the following versions of Splunk® App for Infrastructure (Legacy): 1.3.0, 1.3.1, 1.4.0, 1.4.1, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1 Cloud only, 2.2.0 Cloud only, 2.2.1, 2.2.3 Cloud only, 2.2.4, 2.2.5
Feedback submitted, thanks!