I am observing my license usage in which one index exist which name have "OTHER". Is it by default index or not. Which kind of information it contain? How can see it.
Depending on how you are looking at the usage, you may be using a command like timechart
that lumps everything past the first few results -- 10, generally -- into an OTHER category.
See this one for discussion.
https://answers.splunk.com/answers/390253/how-to-search-the-list-of-hosts-in-the-other-categ.html
Hey @N92, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂
Depending on how you are looking at the usage, you may be using a command like timechart
that lumps everything past the first few results -- 10, generally -- into an OTHER category.
See this one for discussion.
https://answers.splunk.com/answers/390253/how-to-search-the-list-of-hosts-in-the-other-categ.html
main, _internal, _audit
---- these are the 3 indexes that comes defaultly with Splunk deployment.
the "OTHER" index must be created by the person who deployed your splunk.
Which kind of information it contain? --- you can simply look the events this index contain, or which hosts/sources/sourcetypes are there in this index, you can check the Deployment server config files as well
http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Aboutmanagingindexes
In addition to the main index, Splunk Enterprise comes preconfigured with a number of internal indexes. Internal indexes are named starting with an underscore (_). To see a full list of indexes in Splunk Web, click the Settings link in the upper portion of Splunk Web and then select Indexes. The list includes:
main: The default Splunk Enterprise index. All processed external data is stored here unless otherwise specified.
_internal: This index includes Splunk Enterprise internal logs and metrics.
_audit: Events from the file system change monitor, auditing, and all user search history.