Splunk Search

How do I search for a list of Saves searches that don't use index name for searching in Splunk Ent. or ES. Thank u a lot

SamHTexas
Builder

I need to find a list of saved searches that don't use the index name in searching please. Any way to list the name of the users with this list, any cool SPLs ? Thank u in advance. Much appreciated.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean "don't use an index"? You can quite easily find searches which don't have said index literarily entered as a part of the search but what if the searches reference that index in another way? A macro, for example. Or a subsearch?

BTW, just because a search doesn't use a "index=something" condition, doesn't mean that it's "bad". You might - for example have searches populating lookups by performing ldapsearch. Or you might use a search to check a dynamicaly created lookup for its validity of some kind. Or any other legit reason not to have an index explicitly included i  the search.

0 Karma

codebuilder
Influencer

Try this:

| rest /servicesNS/-/-/saved/searches | search search!=*index* |table search eai:acl.owner is_scheduled
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

SamHTexas
Builder

Thx bro for your reply. From your point of view what issues do u see if a search is not using an Index name? Am looking from a Security point of view? Thanks again.

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Probably the biggest issue is that you didn’t know which indexes the query is using (or better to say which it should use). As @PickleRick @said there are many ways to define which index it should use other than index=abc (e.g. eventtypes, auth config files, macros etc.). As those can changed time by time, you couldn’t know later on which indexes are used (should use) by querying that from logs.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...