Splunk Search

List of existing indexes

Sailesh6891
Engager

Is it possible to get list of all indexes with creation time and who created the index?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Sailesh6891 

To list all Splunk indexes, use the search command

1)  | metadata type=indexes 

2) | rest /services/data/indexes 

3)  | tstats count where index=* by index

4)  with web UI access available(if you have admin access), check Settings > Indexes for a managed view. 

 

for the question - creation time and who created the index

there are no straight forward answer for this(should check about this).  

 

Similar question discussed was: https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-get-a-list-of-available-indices/m-p/...

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

PickleRick
SplunkTrust
SplunkTrust

That thread is the one I took liberty of "detaching" the post from since it adds additional elements (creator and creation date) to make it unique.

PickleRick
SplunkTrust
SplunkTrust

There is no such thing as a general "index creation time". And the case of index creator is even more murky if you take into account that indexes can be created by simply creating a config file and restarting the service. Splunk on its own doesn't keep such info directly "attached" to the index. You could try to retrieve events regarding index creation from the _internal index but you are obviously limited to the index's retention period.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...