Knowledge Management

Is there a way to be able to identify the indexes that are being used by app?

aecruzp
Path Finder

good morning

    Is there a way to be able to identify the indexes that are being used by APP?., Currently we are working in a cluster but the query we have only identifies the indexes declared by app in the master server 😞

   Any help will be appreciated

regards

Tags (1)
0 Karma

thebeno
Explorer

What about this:
(oi_vmware is the index name)

| rest /servicesNS/-/-/saved/searches
| search ( search="*oi_vmware*" )
| fields title author eai:acl.app eai:acl.app request.ui_dispatch_app request.ui_dispatch_app eai:acl.sharing id

0 Karma

dkeck
Influencer

HI,

did you try this?

| rest /servicesNS/-/-/data/indexes | table title eai:acl.app

0 Karma

aecruzp
Path Finder

thanks for your answer, this query identifies the indexer.conf statement of the master server and what we need is if a user performs a query in any app using a particular index, know in which app the dashboard or .xml is created

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...