I am trying to better learn what data is in the indexes at my company. There is a command that gives you something like a summary of an index (or index and source type), but I forget that it is called. I do not want to create a summary index, yet that is all I can find when I search.
The command better shows what appears in the left hand side (Interesting Fields) after a search. You can filter it and do other things to give a better understanding of the data.
Thanks,
P.S.
I would also be interested in any ideas people may have for learning the data at a new company. I am a power user, not admin. I found a query to list all indexes and one to list details of all alerts. Is there a way to search all dashboards or display all searches in them?
Perhaps you're thinking of the fieldsummary command (https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchReference/Fieldsummary).
You can use REST to search dashboards
| rest /services/data/ui/views splunk_server=local | table eai:acl.app label title eai:data
I like to make a list of available sourcetypes when I'm learning what data is available.
| metadata type=sourcetypes index=* | table sourcetype
fieldsummary was what I was looking for. Also thanks for the other two searches.
Perhaps you're thinking of the fieldsummary command (https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchReference/Fieldsummary).
You can use REST to search dashboards
| rest /services/data/ui/views splunk_server=local | table eai:acl.app label title eai:data
I like to make a list of available sourcetypes when I'm learning what data is available.
| metadata type=sourcetypes index=* | table sourcetype