Splunk Search

View Summary Index query

deepak02
Path Finder

Hi,

I have been handed over a bunch of summary indexes I should be using as base.

I have full access to the Search Heads.

Is there anyway I can view the queries used by the summary indexes given their names (since the person has already left)?

Thanks,
Deepak

Note: I am using Splunk Enterprise.

Tags (1)
0 Karma
1 Solution

rphillips_splk
Splunk Employee
Splunk Employee

@deepak02 you can use the REST api endpoint for saved searches and look for those which have summary indexing enabled:

run this search:
| rest /servicesNS/-/-/saved/searches | search action.summary_index=1 | table title qualifiedSearch action.summary_index

View solution in original post

0 Karma

somesoni2
Revered Legend

If the owner of saved search using summary index has left and his account is deleted/disabled, you might not be able to search REST API endpoint. REST API approach would be better one if it can work though. If it doesn't and if you can query filesystem on the search head, I would try following grep command to locate searches using a particular summary index.

from $Splunk_Home/etc/apps and $Splunk_Home/etc/users (for private searches)

grep -Hir "action.summary_index._name\s*=\s*<your summary index name here>" | grep savedsearches.conf

This would give you list of savedsearches.conf which contains the searches (which you need to open manually).

0 Karma

deepak02
Path Finder

Works 🙂

Awarded points for the additional info provided.

0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

@deepak02 you can use the REST api endpoint for saved searches and look for those which have summary indexing enabled:

run this search:
| rest /servicesNS/-/-/saved/searches | search action.summary_index=1 | table title qualifiedSearch action.summary_index

0 Karma

deepak02
Path Finder

Works beautifully! Thankyou very much

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...