<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find a index are used in reports, alerts and dashboards? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/693208#M235887</link>
    <description>&lt;P&gt;I have similar issue. The data we had coming into one of our indexes, has now switched to a different format and slightly different field/value pairs. Now I am tasked with finding, where this index/data is being used in lookups, reports, alerts, etc.... So we can change the SPL To match the new data.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 18:03:04 GMT</pubDate>
    <dc:creator>bwheelerice</dc:creator>
    <dc:date>2024-07-12T18:03:04Z</dc:date>
    <item>
      <title>How to find a index are used in reports, alerts and dashboards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/676946#M231494</link>
      <description>&lt;P&gt;It there any best way to find if an index used in any of the saved searches, alerts, reports and dashboard&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 08:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/676946#M231494</guid>
      <dc:creator>susinkumar</dc:creator>
      <dc:date>2024-02-08T08:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a index are used in reports, alerts and dashboards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/676949#M231496</link>
      <description>&lt;P&gt;There is no simple answer to this. You can use the ReST interface to find all the views (dashboards) and look through the code to find the searches, but even then, indexes may be obfuscated through the use of macros, etc. Having found dashboards with definitions that reference indexes, you might want to check whether anyone actually uses the dashboards. Same gores for reports, alerts, etc.&lt;/P&gt;&lt;P&gt;Perhaps you need to narrow down your question. Are you interested in whether a particular index is used? What is your ultimate aim?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 09:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/676949#M231496</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-02-08T09:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a index are used in reports, alerts and dashboards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/677002#M231505</link>
      <description>Hi&lt;BR /&gt;An old answer &lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-find-which-indexes-are-used/m-p/674463" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-find-which-indexes-are-used/m-p/674463&lt;/A&gt; which answer to your questions too.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 08 Feb 2024 19:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/677002#M231505</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-08T19:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a index are used in reports, alerts and dashboards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/677787#M231763</link>
      <description>&lt;P&gt;Yes, I need to check if a&lt;SPAN&gt;&amp;nbsp;particular index is used in any TA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 11:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/677787#M231763</guid>
      <dc:creator>susinkumar</dc:creator>
      <dc:date>2024-02-16T11:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a index are used in reports, alerts and dashboards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/677814#M231772</link>
      <description>As it has said earlier you couldn't get 100% sure answer for this. You should look those old answers to see what you could try to get some answers.</description>
      <pubDate>Fri, 16 Feb 2024 15:20:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/677814#M231772</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-16T15:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a index are used in reports, alerts and dashboards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/693208#M235887</link>
      <description>&lt;P&gt;I have similar issue. The data we had coming into one of our indexes, has now switched to a different format and slightly different field/value pairs. Now I am tasked with finding, where this index/data is being used in lookups, reports, alerts, etc.... So we can change the SPL To match the new data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 18:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-a-index-are-used-in-reports-alerts-and-dashboards/m-p/693208#M235887</guid>
      <dc:creator>bwheelerice</dc:creator>
      <dc:date>2024-07-12T18:03:04Z</dc:date>
    </item>
  </channel>
</rss>

