Splunk Dev

How to check the most accessed/searched index/sourcetypes/source by user..?

prakash007
Builder

Need some help with splunk query, how do we determine the most accessed or least accessed or searched index/sourcetype/source by user. Based on this we will can make use of the license to on-board new logs to splunk.

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

This is the query that can give that information but there is a huge gap in this method, as some (or I must say most) of searches don’t even specify index/sourcetypes.

index=_audit action=search search=* sourcetype=audittrail  | rex field=search "sourcetype\s*=\s*\"*(?<SourcetypeUsed>[^\s\"]+)"  | rex field=search "index\s*=\s*\"*(?<IndexUsed>[^\s\"]+)" | search IndexUsed=* OR SourcetypeUsed=* | fillnull value="NA" IndexUsed SourcetypeUsed| stats count values(search) by IndexUsed SourcetypeUsed

View solution in original post

somesoni2
Revered Legend

This is the query that can give that information but there is a huge gap in this method, as some (or I must say most) of searches don’t even specify index/sourcetypes.

index=_audit action=search search=* sourcetype=audittrail  | rex field=search "sourcetype\s*=\s*\"*(?<SourcetypeUsed>[^\s\"]+)"  | rex field=search "index\s*=\s*\"*(?<IndexUsed>[^\s\"]+)" | search IndexUsed=* OR SourcetypeUsed=* | fillnull value="NA" IndexUsed SourcetypeUsed| stats count values(search) by IndexUsed SourcetypeUsed

prakash007
Builder

Thanks... so, the numbers in the count represents no.of users...?

0 Karma

somesoni2
Revered Legend

Number in the count represents number of searches execution which are using that index/sourcetype. I believe a user field is also there so throwing a dc(user) in the stats will give the count of users.

0 Karma

prakash007
Builder

Got it, Thanks...but as you said some of the searches don't even specify index/sourcetypes.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...