Splunk® App for Infrastructure

Administer Splunk App for Infrastructure

Download manual as PDF

Download topic as PDF

Manage and debug the local server in Splunk App for Infrastructure

Only admins with permission to view the _internal index data can access this troubleshooting feature.

Manage server settings for SAI, including viewing internal server log data to better understand the environment when experiencing issues around data collection, performance issues, and so on. You can also restart your instance to reset server logging.

Investigate internal log data

  1. Go to Settings > Server settings.
  2. Under Server Logging, click the Investigate button. The Analysis Workspace displays with the _internal index log data.
  3. Select a log or logs to display in the workspace. A chart for each selected log displays.
  4. Actions you can perform:
    1. Hover your cursor over an area of the chart to display count and event time information.
    2. Click the expand view icon in the upper right of the chart to display detailed time and event information.
    3. Click the ellipsis icon to save a report, clone the panel, or export as a .png or .csv file.
    4. Use the Split by and Filters in the right panel to filter the log data in the chart.

Restart the server

  1. Go to Settings > Server settings.
  2. Click Restart Splunk.
  3. Confirm you want to restart Splunk. Click Restart.
PREVIOUS
Admin and user roles in Splunk App for Infrastructure
  NEXT
Delete inactive entities

This documentation applies to the following versions of Splunk® App for Infrastructure: 1.3.0, 1.3.1, 1.4.0, 1.4.1, 2.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters