Splunk Search

validate that index is not being queried in splunk

efaundez
Path Finder

Good afternoon

   I can validate in the MC which index have events and which do not, but is it possible to know which index is not being consulted by users? this would let you know that data is not being used and possibly delete it.

Your support is appreciated

0 Karma

codebuilder
Influencer

You can use the following as a base search, then examine the fields available to narrow down to what you're looking for.

index=_audit action=search sourcetype=audittrail
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...