<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a query to identify underused fields? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744255#M22087</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266305"&gt;@Kenny_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately this is not something which is possible.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen some attempts at this previously, however it is very easy to miss things, as specific fields are not always referenced but could be used, such as the following examples:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A _raw event could be presented in a dashboard in a scenario - viewer may use this to determine something.&lt;/LI&gt;&lt;LI&gt;A raw event may be emailed as an alert to a user to take action on something based on something inside the event.&lt;/LI&gt;&lt;LI&gt;Use of wildcards such as &lt;STRONG&gt;| table my_*&lt;/STRONG&gt; or &lt;STRONG&gt;stats values(*) as *&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 16 Apr 2025 06:46:27 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-04-16T06:46:27Z</dc:date>
    <item>
      <title>Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744211#M22085</link>
      <description>&lt;P&gt;Is there a query to identify underused fields?&amp;nbsp;&lt;BR /&gt;We are optimizing the size of our large indexes. we identified duplicates and noisy logs, but next we want to possibly find fields that arent commonly used and get rid of them. (or if you have any additional advise on cleaning out a large index)&lt;BR /&gt;&lt;BR /&gt;is there a query for this?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 20:32:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744211#M22085</guid>
      <dc:creator>Kenny_splunk</dc:creator>
      <dc:date>2025-04-15T20:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744255#M22087</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266305"&gt;@Kenny_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately this is not something which is possible.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen some attempts at this previously, however it is very easy to miss things, as specific fields are not always referenced but could be used, such as the following examples:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A _raw event could be presented in a dashboard in a scenario - viewer may use this to determine something.&lt;/LI&gt;&lt;LI&gt;A raw event may be emailed as an alert to a user to take action on something based on something inside the event.&lt;/LI&gt;&lt;LI&gt;Use of wildcards such as &lt;STRONG&gt;| table my_*&lt;/STRONG&gt; or &lt;STRONG&gt;stats values(*) as *&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 06:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744255#M22087</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-16T06:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744283#M22091</link>
      <description>&lt;P&gt;understood, would you happen to have any advice on cleaning a big index?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 14:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744283#M22091</guid>
      <dc:creator>Kenny_splunk</dc:creator>
      <dc:date>2025-04-16T14:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744299#M22092</link>
      <description>&lt;P&gt;The best options is to define your use cases and based on those remove unused values before indexing events into disk. But this leads you a situation when you realize a new use case then you must update your indexing definitions to get a new values into splunk.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;One thing what you could look is to check that those events don’t contain same information twice or even more times. This can happen when you have some code on your data and then the same information has added as a clear text. A good example is Windows event logs where this happens.&lt;/P&gt;&lt;P&gt;There are also some other cases what you could do like&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;remove additional formatting like json objects contain additional spaces&lt;/LI&gt;&lt;LI&gt;remove unnecessary line breaks&lt;/LI&gt;&lt;LI&gt;check if you could utilize metrics indexes for some data instead of putting everything in event indexes&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 16 Apr 2025 16:07:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744299#M22092</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-16T16:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744311#M22095</link>
      <description>&lt;P&gt;It should be stated up-front that indexes cannot be reduced in size.&amp;nbsp; You must wait for buckets to be frozen for data to go away.&amp;nbsp; The best you can do is reduce how much is stored in new buckets.&lt;/P&gt;&lt;P&gt;You've already taken a good first step by eliminating duplicate events.&lt;/P&gt;&lt;P&gt;Next, look at indexed fields.&amp;nbsp; Fields are best extracted at search-time rather than at index-time.&amp;nbsp; Doing so helps indexer performance, saves space in the indexes, and offers more flexibility with fields.&lt;/P&gt;&lt;P&gt;Look at the INDEXED_EXTRACTIONS settings in your props.conf files. Each of them will create index-time fields.&amp;nbsp; JSON data is especially verbose so KV_MODE=json should be used, instead.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 17:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744311#M22095</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-16T17:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744313#M22096</link>
      <description>&lt;P&gt;yeah we make adjustments with new indexes, however, the large indexes were created before i got hired. so im actively trying to reduce ingest with whats already flowing. great advice btw.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 17:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744313#M22096</guid>
      <dc:creator>Kenny_splunk</dc:creator>
      <dc:date>2025-04-16T17:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a query to identify underused fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744342#M22100</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266305"&gt;@Kenny_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really the only way to "clean" an index is for the data be aged-out. Running the "| delete" on an index will stop it appearing in searches however it will still be present on the disks, just with markers that stop it being returned, therefore it wont actually give you any space back if this is what you are looking for.&lt;/P&gt;&lt;P&gt;The best thing you can do is control the data arriving in the platform and reduce this as necessary, hopefully over time the older/larger/waste data will age out and free up space.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is your retention on this index(es)? If its something like 90 days then you wont have too long to wait, but if its 6 years then you might be stuck with that old data for some time!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 21:41:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-there-a-query-to-identify-underused-fields/m-p/744342#M22100</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-16T21:41:50Z</dc:date>
    </item>
  </channel>
</rss>

