Splunk® App for Infrastructure (Legacy)

Administer Splunk App for Infrastructure

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Manage and debug the local server in Splunk App for Infrastructure

Only admins with permission to view the _internal index data can access this troubleshooting feature.

Manage server settings for SAI, including viewing internal server log data to better understand the environment when experiencing issues around data collection, performance issues, and so on. You can also restart your instance to reset server logging.

Investigate internal log data

  1. Go to Settings > Server settings.
  2. Under Server Logging, click the Investigate button. The Analysis Workspace displays with the _internal index log data.
  3. Select a log or logs to display in the workspace. A chart for each selected log displays.
  4. Actions you can perform:
    1. Hover your cursor over an area of the chart to display count and event time information.
    2. Click the expand view icon in the upper right of the chart to display detailed time and event information.
    3. Click the ellipsis icon to save a report, clone the panel, or export as a .png or .csv file.
    4. Use the Split by and Filters in the right panel to filter the log data in the chart.

Restart the server

  1. Go to Settings > Server settings.
  2. Click Restart Splunk.
  3. Confirm you want to restart Splunk. Click Restart.
Last modified on 08 July, 2020
PREVIOUS
The status of an entity is not updating
 

This documentation applies to the following versions of Splunk® App for Infrastructure (Legacy): 1.3.0, 1.3.1, 1.4.0, 1.4.1, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1 Cloud only, 2.2.0 Cloud only, 2.2.1, 2.2.3 Cloud only, 2.2.4, 2.2.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters