Knowledge Management

How to get details regarding the deleted index?

vin02
Path Finder

One of the index(eg. index= test) has been deleted from the environment. which log i have to check for the respective details.

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion
0 Karma

adonio
Ultra Champion

alt text

0 Karma

adonio
Ultra Champion

try this:

index = _audit user=* action=indexes_edit
index = _internal  component=IndexWriter message="*Initializin*" component=IndexWriter | table _time idx 

Or this:

index = _audit user=* action=indexes_edit object=* | table user action object

hope it helps

0 Karma

vin02
Path Finder

Thanks for your response. but when i am adding my index name ,not getting any result

0 Karma

vin02
Path Finder

If my index name has been changed or deleted then how do i know?

0 Karma

adonio
Ultra Champion

Can you share how you are adding your index name in search?
I am attaching a screenshot on the answer below with an index i first created, then edited and then modified and then removed.
is it a single indexer? couple of them? indexer cluster?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...