06. Splunk Tutorials |Splunk Admin| Splunk Developer| What is an Index and Default indexes in Splunk

preview_player
Показать описание
1) _audit : Includes events from the file system, auditing and all user search history

2) _internal : Includes Splunk internal logs and metrics

3) main : It’s a default index. All processed external data will be stored here if user doesn’t specify any index

4) _configtracker : contains data about the changes to the splunk enterprise configuration files.

5) _introspection : contains the data about the Splunk enterprise instance and environment

6) _metrics : contains system metrics data such as CPU, memory or disk

7) _telemetry : License usage summary logs

8) _thefishbucket : Data read by splunk are stored in fish bucket
Рекомендации по теме
visit shbcf.ru