Deployment Architecture

How to get the details of index name and who has created it ?

gndivya
Explorer

Is it possible to get the list of all indexes along with the userID who has created that index with the time of creation?
I have tried with | rest /services/data/indexes, where index details (cold, hot, thawed paths) are available but not the creation timestamp and user id.

0 Karma
1 Solution

woodcock
Esteemed Legend

You cannot get this information directly. You could deploy a scripted input to your indexers that does a ls -al /path/to/hot /path/to/cold but this is only going to show you that user splunk owns it. It should show you the creation date, though.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You cannot get this information directly. You could deploy a scripted input to your indexers that does a ls -al /path/to/hot /path/to/cold but this is only going to show you that user splunk owns it. It should show you the creation date, though.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...