Splunk Dev

How to check the most accessed/searched index/sourcetypes/source by user..?

prakash007
Builder

Need some help with splunk query, how do we determine the most accessed or least accessed or searched index/sourcetype/source by user. Based on this we will can make use of the license to on-board new logs to splunk.

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

This is the query that can give that information but there is a huge gap in this method, as some (or I must say most) of searches don’t even specify index/sourcetypes.

index=_audit action=search search=* sourcetype=audittrail  | rex field=search "sourcetype\s*=\s*\"*(?<SourcetypeUsed>[^\s\"]+)"  | rex field=search "index\s*=\s*\"*(?<IndexUsed>[^\s\"]+)" | search IndexUsed=* OR SourcetypeUsed=* | fillnull value="NA" IndexUsed SourcetypeUsed| stats count values(search) by IndexUsed SourcetypeUsed

View solution in original post

somesoni2
Revered Legend

This is the query that can give that information but there is a huge gap in this method, as some (or I must say most) of searches don’t even specify index/sourcetypes.

index=_audit action=search search=* sourcetype=audittrail  | rex field=search "sourcetype\s*=\s*\"*(?<SourcetypeUsed>[^\s\"]+)"  | rex field=search "index\s*=\s*\"*(?<IndexUsed>[^\s\"]+)" | search IndexUsed=* OR SourcetypeUsed=* | fillnull value="NA" IndexUsed SourcetypeUsed| stats count values(search) by IndexUsed SourcetypeUsed

prakash007
Builder

Thanks... so, the numbers in the count represents no.of users...?

0 Karma

somesoni2
Revered Legend

Number in the count represents number of searches execution which are using that index/sourcetype. I believe a user field is also there so throwing a dc(user) in the stats will give the count of users.

0 Karma

prakash007
Builder

Got it, Thanks...but as you said some of the searches don't even specify index/sourcetypes.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...