Hi @wrbeleli,
You can use below sample search;
| rest /services/data/indexes
| search NOT title=_*
| table title
| search NOT
[| rest /services/authorization/roles
| where NOT match(srchIndexesAllowed,"\*+")
| rename srchIndexesAllowed as title
| dedup title
| fields title ]
Usually, the easiest way to get info about splunk config items is with | rest command.
In this case you're interested in https://docs.splunk.com/Documentation/Splunk/8.2.2/RESTREF/RESTintrospect#data.2Findexes endpoint.