Hello ,
I'm trying to identify the total list of indexes have been created in the Splunk (all this year ) , i have used below query to find out , but looks like this is not correct
index = _audit operation=create
| stats values(object) as new_index_created by _time splunk_server
| rename _time as creation_time splunk_server as indexer|convert ctime(creation_time)|dedup new_index_created
any inputs ?