Splunk Enterprise

How to view the Indexes.conf parameters from a SPL statement?

itsmevic
Communicator

Hello Splunkers! 

     How would one view the parameters of the indexes.conf by using a SPL statement?  The below SPL statement doesn't seem to work.  Any help is greatly appreciated! 

| rest splunk_server=<hostname>/services/configs/conf-indexes
| transpose

Labels (1)
Tags (1)
0 Karma

m_pham
Splunk Employee
Splunk Employee

I copied your SPL and it didn't have a space between the endpoint and splunk_server values. Can you try this?

| rest splunk_server=<my_hosts> /services/configs/conf-indexes
0 Karma

Stefanie
Builder

The query works for me. Are you putting a space between the hostname and /services/configs/conf-indexes? 

 

Maybe another option is to use the commandline and use btool? 

$SPLUNK_HOME/bin/splunk btool indexes list

 

itsmevic
Communicator

Let me try the query again, maybe I fat-fingered it.  

0 Karma

itsmevic
Communicator

I would totally agree with you on any other occasion; however,  If I had access to the backend, I def would be running your CLI suggestion, but I do not, so I need to do this through the front end.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...