Splunk Search

How to find a index are used in reports, alerts and dashboards?

susinkumar
Engager

It there any best way to find if an index used in any of the saved searches, alerts, reports and dashboard

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
An old answer https://community.splunk.com/t5/Splunk-Search/How-to-find-which-indexes-are-used/m-p/674463 which answer to your questions too.
r. Ismo
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

There is no simple answer to this. You can use the ReST interface to find all the views (dashboards) and look through the code to find the searches, but even then, indexes may be obfuscated through the use of macros, etc. Having found dashboards with definitions that reference indexes, you might want to check whether anyone actually uses the dashboards. Same gores for reports, alerts, etc.

Perhaps you need to narrow down your question. Are you interested in whether a particular index is used? What is your ultimate aim?

0 Karma

susinkumar
Engager

Yes, I need to check if a particular index is used in any TA.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As it has said earlier you couldn't get 100% sure answer for this. You should look those old answers to see what you could try to get some answers.
0 Karma

bwheelerice
Engager

I have similar issue. The data we had coming into one of our indexes, has now switched to a different format and slightly different field/value pairs. Now I am tasked with finding, where this index/data is being used in lookups, reports, alerts, etc.... So we can change the SPL To match the new data. 

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...