Splunk Search

How to find a index are used in reports, alerts and dashboards?

susinkumar
Engager

It there any best way to find if an index used in any of the saved searches, alerts, reports and dashboard

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
An old answer https://community.splunk.com/t5/Splunk-Search/How-to-find-which-indexes-are-used/m-p/674463 which answer to your questions too.
r. Ismo
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

There is no simple answer to this. You can use the ReST interface to find all the views (dashboards) and look through the code to find the searches, but even then, indexes may be obfuscated through the use of macros, etc. Having found dashboards with definitions that reference indexes, you might want to check whether anyone actually uses the dashboards. Same gores for reports, alerts, etc.

Perhaps you need to narrow down your question. Are you interested in whether a particular index is used? What is your ultimate aim?

0 Karma

susinkumar
Engager

Yes, I need to check if a particular index is used in any TA.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As it has said earlier you couldn't get 100% sure answer for this. You should look those old answers to see what you could try to get some answers.
0 Karma

bwheelerice
Engager

I have similar issue. The data we had coming into one of our indexes, has now switched to a different format and slightly different field/value pairs. Now I am tasked with finding, where this index/data is being used in lookups, reports, alerts, etc.... So we can change the SPL To match the new data. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...