Splunk Search
Highlighted

How do I search for a list of the most searched indexes and the count for each?

Communicator

Hi,

I am looking for a list of the most searched indexes and the count for each. Is it possible to get that in Splunk?

Can someone please share a search for that?

Tags (3)
0 Karma
Highlighted

Re: How do I search for a list of the most searched indexes and the count for each?

Community Manager
Community Manager

Hi @rameshlpatel

Can you clarify if you're looking for a list of the most searched indexers or most searched indexes? You put "indexes list" in your title but "indexer list" in your content.

0 Karma
Highlighted

Re: How do I search for a list of the most searched indexes and the count for each?

Communicator

My Bad. most searched indexes .

0 Karma
Highlighted

Re: How do I search for a list of the most searched indexes and the count for each?

Community Manager
Community Manager

No problem, thanks for clarifying!

0 Karma
Highlighted

Re: How do I search for a list of the most searched indexes and the count for each?

SplunkTrust
SplunkTrust

Something like this can get you started

index=_audit action=*search*  search_id=* | table _time search  splunk_server | rex field=search "index\s*=\s*(?<IndexName>\w+)" | stats count by IndexName splunk_server

View solution in original post