Getting Data In

Describtion of _internal index fields - /opt/splunk/var/log/splunk/license_usage.log

mbschriek
Explorer

Is there some documentation including the definition and description of fields in the _internal index.

For example:
- /opt/splunk/var/log/splunk/license_usage.log

field;
- h
- i
- idx
- s
- st

Kind regards,

Tags (1)
1 Solution

javiergn
Super Champion

I don't think so but in your particular case:

  • h -> host
  • i -> license slave instance (you can find them here: | rest splunk_server=local /services/licenser/slaves)
  • idx -> index
  • s -> source
  • st -> sourcetype

In general you can either guess what the fields are or simply look for existing Splunk searches and how they are used to find what you are looking.

Maybe the following links can help too:

https://answers.splunk.com/answers/194456/is-there-a-guide-or-map-to-understand-splunks-inte.html
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself

Regards,
J

View solution in original post

javiergn
Super Champion

I don't think so but in your particular case:

  • h -> host
  • i -> license slave instance (you can find them here: | rest splunk_server=local /services/licenser/slaves)
  • idx -> index
  • s -> source
  • st -> sourcetype

In general you can either guess what the fields are or simply look for existing Splunk searches and how they are used to find what you are looking.

Maybe the following links can help too:

https://answers.splunk.com/answers/194456/is-there-a-guide-or-map-to-understand-splunks-inte.html
http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself

Regards,
J

mbschriek
Explorer

Thanks for the reply. I guessed the same field descriptions, still it's strange that there is no elaborated documentation about these inputs.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...