<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: validate that index is not being queried in splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/validate-that-index-is-not-being-queried-in-splunk/m-p/491345#M137169</link>
    <description>&lt;P&gt;You can use the following as a base search, then examine the fields available to narrow down to what you're looking for.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit action=search sourcetype=audittrail
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 05 May 2020 16:08:51 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2020-05-05T16:08:51Z</dc:date>
    <item>
      <title>validate that index is not being queried in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/validate-that-index-is-not-being-queried-in-splunk/m-p/491344#M137168</link>
      <description>&lt;P&gt;Good afternoon&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp; I can validate in the MC which index have events and which do not, but is it possible to know which index is not being consulted by users? this would let you know that data is not being used and possibly delete it.&lt;/P&gt;

&lt;P&gt;Your support is appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 14:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/validate-that-index-is-not-being-queried-in-splunk/m-p/491344#M137168</guid>
      <dc:creator>efaundez</dc:creator>
      <dc:date>2020-05-05T14:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: validate that index is not being queried in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/validate-that-index-is-not-being-queried-in-splunk/m-p/491345#M137169</link>
      <description>&lt;P&gt;You can use the following as a base search, then examine the fields available to narrow down to what you're looking for.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit action=search sourcetype=audittrail
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 05 May 2020 16:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/validate-that-index-is-not-being-queried-in-splunk/m-p/491345#M137169</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-05-05T16:08:51Z</dc:date>
    </item>
  </channel>
</rss>

