Getting Data In

Search that lists the configured indexes on a Splunk indexer?

Derek
Path Finder

Hi,

Is there a search that can return the list of indexes configured on a Splunk Indexer?

Or is the only way to look at the _internal index and work it out based on data that exists in that index from performance metrics etc..

Thanks!

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You can run | eventcount summarize=false index=* index=_*. This search actually runs distributed, but it does add a field splunk_server so you can sort or filter on that.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

You can run | eventcount summarize=false index=* index=_*. This search actually runs distributed, but it does add a field splunk_server so you can sort or filter on that.

Simeon
Splunk Employee
Splunk Employee

If you have no more than 8 indexes, you can do the following:

index=_internal source=*metrics.log* per_index_thruput | stats count by series

The above search grabs indexing metrics from the internal logs. By default, Splunk will only track the top 10 indexes including the two internal ones (_internal and _audit). If you have more than 10 indexes, you can change the metrics logging limit.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...