Something like this can get you started
index=_audit action=*search* search_id=* | table _time search splunk_server | rex field=search "index\s*=\s*(?<IndexName>\w+)" | stats count by IndexName splunk_server
Something like this can get you started
index=_audit action=*search* search_id=* | table _time search splunk_server | rex field=search "index\s*=\s*(?<IndexName>\w+)" | stats count by IndexName splunk_server
Hi @rameshlpatel
Can you clarify if you're looking for a list of the most searched indexers or most searched indexes? You put "indexes list" in your title but "indexer list" in your content.
My Bad. most searched indexes .
No problem, thanks for clarifying!