Monitoring Components

Everything TrackMe tracks is an entity, and every entity belongs to one of seven monitoring components. The component decides what is measured and which tracking logic applies. This part introduces the shared model, gives each component its own page, then covers the advanced tracker types that extend them.

  • Overview — the seven components at a glance, the shared entity lifecycle, and how to choose between them.

  • DSM, DHM, MHM — the data-flow family (“is my data arriving?”).

  • VOL — is my license volume normal? Drops, spikes and silence on the licensed volume of every index, with a trend and a month projection.

  • FLX — track anything you can express in SPL.

  • FQM — is my data well-parsed and CIM-compliant?

  • WLK — are my scheduled searches healthy?

  • UAM (Beta) — Who is doing what on my Splunk? A dedicated tenant type outside the seven entity components: the accounts, their scheduled searches, their activity and their resource usage, turned into findings.

  • Hybrid & replica trackers — advanced tracker types that feed entities into those components: build a tracker from your own SPL (local or remote), or mirror entities from another TrackMe deployment.