Introduction

This part of the Product Guide gives you the mental model you need before configuring anything. Read it once, top to bottom — it is short — and the rest of the guide will make sense the first time.

  • Overview — what TrackMe is, who it is for, and what it does for your Splunk platform.

  • Core concepts — the vocabulary used everywhere else in this guide: entities, components, virtual tenants, state and score, policies, trackers.

  • How TrackMe works — the monitoring cycle that turns raw index=… activity into per-entity states, scores, and alerts.

  • Navigating the UI — an in-depth visual tour of the TrackMe interface.

Tip

New to TrackMe and want to get something running first? Start with the Quickstart, then come back here when you want to understand why it works the way it does.