Splunk Dev

How to check the most accessed/searched index/sourcetypes/source by user..?

prakash007
Builder

Need some help with splunk query, how do we determine the most accessed or least accessed or searched index/sourcetype/source by user. Based on this we will can make use of the license to on-board new logs to splunk.

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

This is the query that can give that information but there is a huge gap in this method, as some (or I must say most) of searches don’t even specify index/sourcetypes.

index=_audit action=search search=* sourcetype=audittrail  | rex field=search "sourcetype\s*=\s*\"*(?<SourcetypeUsed>[^\s\"]+)"  | rex field=search "index\s*=\s*\"*(?<IndexUsed>[^\s\"]+)" | search IndexUsed=* OR SourcetypeUsed=* | fillnull value="NA" IndexUsed SourcetypeUsed| stats count values(search) by IndexUsed SourcetypeUsed

View solution in original post

somesoni2
Revered Legend

This is the query that can give that information but there is a huge gap in this method, as some (or I must say most) of searches don’t even specify index/sourcetypes.

index=_audit action=search search=* sourcetype=audittrail  | rex field=search "sourcetype\s*=\s*\"*(?<SourcetypeUsed>[^\s\"]+)"  | rex field=search "index\s*=\s*\"*(?<IndexUsed>[^\s\"]+)" | search IndexUsed=* OR SourcetypeUsed=* | fillnull value="NA" IndexUsed SourcetypeUsed| stats count values(search) by IndexUsed SourcetypeUsed

prakash007
Builder

Thanks... so, the numbers in the count represents no.of users...?

0 Karma

somesoni2
Revered Legend

Number in the count represents number of searches execution which are using that index/sourcetype. I believe a user field is also there so throwing a dc(user) in the stats will give the count of users.

0 Karma

prakash007
Builder

Got it, Thanks...but as you said some of the searches don't even specify index/sourcetypes.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...