Splunk Search

Indexes used within the last 30 day

Strangertinz
Path Finder

Hi, 

I am looking for a search to list out all of the indexes in Splunk. I know how to get the full but looking for a clear way to get a list of the ones being used and actively received data within the last 30 days.

 

Thanks in advance!

 

 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Strangertinz ,

you could run a simple search like the following:

| tstats count WHERE index=* BY index

on the last 30 days.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Strangertinz ,

you could run a simple search like the following:

| tstats count WHERE index=* BY index

on the last 30 days.

Ciao.

Giuseppe

dtburrows3
Builder

Probably a few ways of doing this, but if you have access to index=_internal you can try something like this.

index=_internal component=Metrics group=per_index_thruput earliest=-30d@d latest=now
    | bucket span=1h _time
    | stats
        sum(kb) as hourly_kb,
        sum(ev) as hourly_events,
            by _time, series
    | stats
        earliest(_time) as earliest_event,
        latest(_time) as latest_event,
        count as sample_size,
        avg(hourly_kb) as avg_hourly_kb,
        sum(hourly_kb) as total_kb,
        avg(hourly_events) as avg_hourly_events,
        sum(hourly_events) as total_events
            by series
    | convert
        ctime(earliest_event),
        ctime(latest_event)
    | rename
        series as index
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...