Splunk Search

List of the indexes that do not have attached a self-storage

esteban593
Explorer

Hi,

I'm trying to get a query for a table containing all the indexes that do not have a self storage attached, but I couldn't find anything useful. Does anyone has an idea of how to do it?

 

Thanks!

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  I take it this is on Splunk Cloud.  Try this query

| rest splunk_server=local /services/cluster_blaster_indexes/sh_indexes_manager 
| search * 
| where isnull(archiver.selfStorageProvider) 
| table title *self*
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

What do you mean by "do not have a self storage attached"?  What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma

esteban593
Explorer

With that I mean by that are indexes which do not have an S3 bucket attached for backup. When you go to Settings > Indexes and the list is displayed, there's a column called "Self storage".

I want to configure a dashboard that displays all the indexes without self storage attached.

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  I take it this is on Splunk Cloud.  Try this query

| rest splunk_server=local /services/cluster_blaster_indexes/sh_indexes_manager 
| search * 
| where isnull(archiver.selfStorageProvider) 
| table title *self*
---
If this reply helps you, Karma would be appreciated.

esteban593
Explorer

Thanks! This works wonders

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...