Splunk Enterprise

indexes which are not in used in any use case

Path Finder

i want to see which all feeds are there which are not getting used in any use case or in any report/alert or anything.

kindly suggest me the way to check those indexes


Thanks in advance.

Labels (1)
0 Karma

Path Finder

Hi @vinitpathri 

  1. List all the names of indexes



| eventcount summarize=false index=* index=_* | dedup index | fields index​

2. List all the saved searches alerts 




| rest /servicesNS/-/-/saved/searches 
| search is_scheduled=1 
| table title, cron_schedule next_scheduled_time eai:acl.owner actions eai:acl.app action.email action.email.to dispatch.earliest_time dispatch.latest_time search​



3. Compare the search field with the index field by joining these two outputs and running a search command.


Did I get your requirement correct? if yes then I can think of creating a join to give  you desired result 🤔

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...