All Apps and Add-ons

Chargeback app customers.csv audit shows same indexes on "Index defined in customers.csv but NOT defined in Splunk" AND "index is NOT defined in customers.csv.


I cannot figure out why this isn't reporting correctly. We are running Splunk Enterprise 7.1.4. I have updated my Chargeback app to 2.2.1. I have also rerun the initial search which builds the customers.csv file (on a side note, thanks for automating the micro_lic_GB calculation) . The "Indexes Accounted For" report still shows the same indexes in both columns. This is my search:

| set diff [| inputlookup customers.csv | dedup idx | fields idx | search NOT idx=*summary* | rename idx AS "Index defined in customers.csv, but is NOT defined in Splunk"] [| rest /services/data/indexes | search isInternal=0 | search NOT title=*summary* | dedup title | fields title | rename title AS "Index is NOT defined in customers.csv"]

Thanks for the help in advance.


This is happening here as well. Would anyone have any insight to make this search work?

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...