Installation

Why is an index listed as "OTHER" when checking license usage?

N92
Path Finder

I am observing my license usage in which one index exist which name have "OTHER". Is it by default index or not. Which kind of information it contain? How can see it.

Labels (1)
0 Karma
1 Solution

DalJeanis
SplunkTrust
SplunkTrust

Depending on how you are looking at the usage, you may be using a command like timechart that lumps everything past the first few results -- 10, generally -- into an OTHER category.

See this one for discussion.

https://answers.splunk.com/answers/390253/how-to-search-the-list-of-hosts-in-the-other-categ.html

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @N92, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

Depending on how you are looking at the usage, you may be using a command like timechart that lumps everything past the first few results -- 10, generally -- into an OTHER category.

See this one for discussion.

https://answers.splunk.com/answers/390253/how-to-search-the-list-of-hosts-in-the-other-categ.html

inventsekar
Super Champion

main, _internal, _audit ---- these are the 3 indexes that comes defaultly with Splunk deployment.
the "OTHER" index must be created by the person who deployed your splunk.
Which kind of information it contain? --- you can simply look the events this index contain, or which hosts/sources/sourcetypes are there in this index, you can check the Deployment server config files as well

http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Aboutmanagingindexes

In addition to the main index, Splunk Enterprise comes preconfigured with a number of internal indexes. Internal indexes are named starting with an underscore (_). To see a full list of indexes in Splunk Web, click the Settings link in the upper portion of Splunk Web and then select Indexes. The list includes:

main: The default Splunk Enterprise index. All processed external data is stored here unless otherwise specified.
_internal: This index includes Splunk Enterprise internal logs and metrics.
_audit: Events from the file system change monitor, auditing, and all user search history.

PS ... If any post helped you in any way, pls give a hi-five to the author with an upvote. if your issue got resolved, please accept the reply as solution.. thanks.
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...