This document provides examples of searches that can be performed in the _internal index in Splunk to gather operational intelligence and troubleshoot issues. Some examples included finding server roles, search heads, forwarders, deployment client phone homes, scheduler errors, saved search run times and failures, email alert failures, indexing rates, license usage, and search concurrency. The document also provides searches to identify dashboards with concurrent users, who deleted a dashboard, login locations, and searches the audit log for login information.