Splunk Search

Is it possible to get a list of all the Indexes which are used in ITSI and all the related services to those indexes?

Suara
Explorer

Hello Community ! 

Is it possible to get a list of all the Indexes which are used in ITSI and all the related services to those indexes with a SPL ? 

| REST /services/data/indexes | dedup title | sort title | table title     -  I found this to be helpful but it's not the answer which i'm looking for. 

Thank you in advance ! 

Labels (2)
0 Karma
1 Solution

Suara
Explorer

Hello All:

I found the following SPL to do exactly what i needed: 

| inputlookup service_kpi_sbs_lookup
| rex field=kpis.base_search "^.*index=(?<indexUsed>\w+)\s"
| rex field=kpis.base_search "^.*index IN\s\((?<indexUsed>[a-zA-Z_,\s]+)\)\s"
| fields indexUsed kpis.title title
| eval indexUsed=mvdedup(indexUsed) 

Cheers.

View solution in original post

Suara
Explorer

Hello All:

I found the following SPL to do exactly what i needed: 

| inputlookup service_kpi_sbs_lookup
| rex field=kpis.base_search "^.*index=(?<indexUsed>\w+)\s"
| rex field=kpis.base_search "^.*index IN\s\((?<indexUsed>[a-zA-Z_,\s]+)\)\s"
| fields indexUsed kpis.title title
| eval indexUsed=mvdedup(indexUsed) 

Cheers.

richgalloway
SplunkTrust
SplunkTrust

You can find a list of ITSI indexes at https://docs.splunk.com/Documentation/ITSI/4.15.0/Install/Indexes#ITSI_indexes

To find them programmatically, add a filter on eai:acl.app to your query.

| REST /services/data/indexes
| search eai:acl.app="SA-IndexCreation" 
| dedup title 
| sort title 
| table title

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Suara
Explorer

Hello Rich,

Thank you for the reply but i'm trying to figure out an SPL that can list all the indexes which we created excluding the default ones. And i'm trying to investigate if there is an SPL also that can list which Services use which Indexes in our environment. 

I have to create a document that lists all of that for our company 😕

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...