Dashboards & Visualizations

index access and usage statistics / report / dashboard

damucka
Builder

Hello,

I am looking for a way to report on the usage of my index(es), the best of course in a graphically attractive way if possible.

I would be interested in the following KPIs:
- user accesses to the index, per user per time span
- alerts triggered per day - this can be general per my App
- indexed data growth per day per index, or even sourcetype
.. perhaps some other KPIs.

Is there any app that would do this for me? Or perhaps a set of useful SPLs?

Kind Regards,

Kamil

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

there are tons of answers in this portal around an of the topics you are looking for.
do you have access to _internal or _audit indexes?
Do you have a Monitoring Console? (MC) most of it is pre-built
as for your questions:
- user accesses to the index, per user per time span - i think this one is the toughest to solve, here is a direction:
https://answers.splunk.com/answers/321581/how-to-find-the-most-searched-index-in-splunk.html
- alerts triggered per day - this can be general per my App
https://answers.splunk.com/answers/305328/how-to-search-the-names-of-triggered-alerts-their.html
https://answers.splunk.com/answers/577325/how-to-pull-the-details-of-triggered-alert-for-las.html
https://answers.splunk.com/answers/564850/how-can-i-make-a-dashboard-with-all-triggered-aler.html
- indexed data growth per day per index, or even sourcetype
you can use the logic within the firebrigade app https://splunkbase.splunk.com/app/1632/ or other apps that might serve admins
https://answers.splunk.com/answers/23136/index-growth.html
https://answers.splunk.com/answers/716733/how-do-you-calculate-the-growth-of-each-index-on-a.html
https://answers.splunk.com/answers/242759/help-to-find-daily-indexed-data-size-by-each-index.html

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

there are tons of answers in this portal around an of the topics you are looking for.
do you have access to _internal or _audit indexes?
Do you have a Monitoring Console? (MC) most of it is pre-built
as for your questions:
- user accesses to the index, per user per time span - i think this one is the toughest to solve, here is a direction:
https://answers.splunk.com/answers/321581/how-to-find-the-most-searched-index-in-splunk.html
- alerts triggered per day - this can be general per my App
https://answers.splunk.com/answers/305328/how-to-search-the-names-of-triggered-alerts-their.html
https://answers.splunk.com/answers/577325/how-to-pull-the-details-of-triggered-alert-for-las.html
https://answers.splunk.com/answers/564850/how-can-i-make-a-dashboard-with-all-triggered-aler.html
- indexed data growth per day per index, or even sourcetype
you can use the logic within the firebrigade app https://splunkbase.splunk.com/app/1632/ or other apps that might serve admins
https://answers.splunk.com/answers/23136/index-growth.html
https://answers.splunk.com/answers/716733/how-do-you-calculate-the-growth-of-each-index-on-a.html
https://answers.splunk.com/answers/242759/help-to-find-daily-indexed-data-size-by-each-index.html

hope it helps

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...