Splunk Search

Is it possible to get a list of all the Indexes which are used in ITSI and all the related services to those indexes?

Suara
Explorer

Hello Community ! 

Is it possible to get a list of all the Indexes which are used in ITSI and all the related services to those indexes with a SPL ? 

| REST /services/data/indexes | dedup title | sort title | table title     -  I found this to be helpful but it's not the answer which i'm looking for. 

Thank you in advance ! 

Labels (2)
0 Karma
1 Solution

Suara
Explorer

Hello All:

I found the following SPL to do exactly what i needed: 

| inputlookup service_kpi_sbs_lookup
| rex field=kpis.base_search "^.*index=(?<indexUsed>\w+)\s"
| rex field=kpis.base_search "^.*index IN\s\((?<indexUsed>[a-zA-Z_,\s]+)\)\s"
| fields indexUsed kpis.title title
| eval indexUsed=mvdedup(indexUsed) 

Cheers.

View solution in original post

Suara
Explorer

Hello All:

I found the following SPL to do exactly what i needed: 

| inputlookup service_kpi_sbs_lookup
| rex field=kpis.base_search "^.*index=(?<indexUsed>\w+)\s"
| rex field=kpis.base_search "^.*index IN\s\((?<indexUsed>[a-zA-Z_,\s]+)\)\s"
| fields indexUsed kpis.title title
| eval indexUsed=mvdedup(indexUsed) 

Cheers.

richgalloway
SplunkTrust
SplunkTrust

You can find a list of ITSI indexes at https://docs.splunk.com/Documentation/ITSI/4.15.0/Install/Indexes#ITSI_indexes

To find them programmatically, add a filter on eai:acl.app to your query.

| REST /services/data/indexes
| search eai:acl.app="SA-IndexCreation" 
| dedup title 
| sort title 
| table title

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Suara
Explorer

Hello Rich,

Thank you for the reply but i'm trying to figure out an SPL that can list all the indexes which we created excluding the default ones. And i'm trying to investigate if there is an SPL also that can list which Services use which Indexes in our environment. 

I have to create a document that lists all of that for our company 😕

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...