Splunk Search

Is it possible to get a list of all the Indexes which are used in ITSI and all the related services to those indexes?

Suara
Explorer

Hello Community ! 

Is it possible to get a list of all the Indexes which are used in ITSI and all the related services to those indexes with a SPL ? 

| REST /services/data/indexes | dedup title | sort title | table title     -  I found this to be helpful but it's not the answer which i'm looking for. 

Thank you in advance ! 

Labels (2)
0 Karma
1 Solution

Suara
Explorer

Hello All:

I found the following SPL to do exactly what i needed: 

| inputlookup service_kpi_sbs_lookup
| rex field=kpis.base_search "^.*index=(?<indexUsed>\w+)\s"
| rex field=kpis.base_search "^.*index IN\s\((?<indexUsed>[a-zA-Z_,\s]+)\)\s"
| fields indexUsed kpis.title title
| eval indexUsed=mvdedup(indexUsed) 

Cheers.

View solution in original post

Suara
Explorer

Hello All:

I found the following SPL to do exactly what i needed: 

| inputlookup service_kpi_sbs_lookup
| rex field=kpis.base_search "^.*index=(?<indexUsed>\w+)\s"
| rex field=kpis.base_search "^.*index IN\s\((?<indexUsed>[a-zA-Z_,\s]+)\)\s"
| fields indexUsed kpis.title title
| eval indexUsed=mvdedup(indexUsed) 

Cheers.

richgalloway
SplunkTrust
SplunkTrust

You can find a list of ITSI indexes at https://docs.splunk.com/Documentation/ITSI/4.15.0/Install/Indexes#ITSI_indexes

To find them programmatically, add a filter on eai:acl.app to your query.

| REST /services/data/indexes
| search eai:acl.app="SA-IndexCreation" 
| dedup title 
| sort title 
| table title

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Suara
Explorer

Hello Rich,

Thank you for the reply but i'm trying to figure out an SPL that can list all the indexes which we created excluding the default ones. And i'm trying to investigate if there is an SPL also that can list which Services use which Indexes in our environment. 

I have to create a document that lists all of that for our company 😕

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...