Hi,
I want to extract list of all the views,searches, dashboards that use a particular index, say , idx_abc and the fields used in them all.
List of views and searches part is done (open for suggestions) :
List of searches :
| rest timeout=600 splunk_server=local /servicesNS/-/-/saved/searches|eval scheduled=if(is_scheduled=1,"yes","no")|where like(search,"%idx_abc%")|table title search scheduled
List of views :
| rest /servicesNS/-/-/data/ui/views splunk_server=*|rename eai:data as data|where like (data,"%idx_abc%")|table label, data
How to get list of fields used ???
Also , there might be eventtypes and macros making use of idx_abc (though i have checked manually at UI) . Still any idea of a query ?
Thanks,
Shraddha
To find eventtypes using a given index, try |rest /services/saved/eventtypes | where like(search,"%idx_abc%")
.
I'm not aware of a command that retrieves macro definitions.
Getting a list of fields is a problem. Not only is there not a command to do so, every search can create its own fields so any command output would be incomplete.
To find eventtypes using a given index, try |rest /services/saved/eventtypes | where like(search,"%idx_abc%")
.
I'm not aware of a command that retrieves macro definitions.
Getting a list of fields is a problem. Not only is there not a command to do so, every search can create its own fields so any command output would be incomplete.
Thanks,
finding macros:
|rest splunk_server=* /servicesNS/-/-/admin/macros|where like(definition,"%idx_abc%")