Deployment Architecture

Why am I only getting results from the main index instead of all indexes when using the dbinspect command?

ltrand
Contributor

So, when I try to do a straight |dbinspect, I only get results for main instead of for all indexes. This is the same on the search head as it is on the index directly. Any thoughts on where I need to start to get the data? I'm trying to figure out better bucket rotation, but I can't do that unless I can evaluate the buckets.

Thanks everyone!

Tags (3)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi strand,

well the docs http://docs.splunk.com/Documentation/Splunk/6.3.1/SearchReference/Dbinspect are pretty straight forward on this:

index
Syntax: index=<string>
Description: Specify a name of an index to inspect. This option can be repeated for more indexes, and accepts wildcards such as asterisk ( * ) for all non-internal indexes.
Default: The default index, which is typically main.

If you want all available indexes to be shown, run this:

| dbinspect index=*

Hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi strand,

well the docs http://docs.splunk.com/Documentation/Splunk/6.3.1/SearchReference/Dbinspect are pretty straight forward on this:

index
Syntax: index=<string>
Description: Specify a name of an index to inspect. This option can be repeated for more indexes, and accepts wildcards such as asterisk ( * ) for all non-internal indexes.
Default: The default index, which is typically main.

If you want all available indexes to be shown, run this:

| dbinspect index=*

Hope this helps ...

cheers, MuS

ltrand
Contributor

Thanks for the clarification, I wasn't reading the documentation right on that.

0 Karma
Get Updates on the Splunk Community!

Set Up More Secure Configurations in Splunk Enterprise With Config Assist

This blog post is part 3 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...