All Apps and Add-ons

Chargeback app customers.csv audit shows same indexes on "Index defined in customers.csv but NOT defined in Splunk" AND "index is NOT defined in customers.csv.

maandch
Engager

I cannot figure out why this isn't reporting correctly. We are running Splunk Enterprise 7.1.4. I have updated my Chargeback app to 2.2.1. I have also rerun the initial search which builds the customers.csv file (on a side note, thanks for automating the micro_lic_GB calculation) . The "Indexes Accounted For" report still shows the same indexes in both columns. This is my search:

| set diff [| inputlookup customers.csv | dedup idx | fields idx | search NOT idx=*summary* | rename idx AS "Index defined in customers.csv, but is NOT defined in Splunk"] [| rest /services/data/indexes | search isInternal=0 | search NOT title=*summary* | dedup title | fields title | rename title AS "Index is NOT defined in customers.csv"]

Thanks for the help in advance.

manderson7
Contributor

This is happening here as well. Would anyone have any insight to make this search work?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...