We have a Splunk Enterprise License. I wanted to know about the log lines that are never viewed through the Splunk UI. I need this detail to do analyses on log patterns that were never viewed and to come up with the best practice to avoid such logs.
I have the below details. All the queries that are used till this point of time.
Adhoc queries
Dashboard queries
Report queries
Scheduled queries
Theoretically, if I exclude the above results from the whole set, I should get the logs that are never queried. I can write a java program to get the queried results, but how do I find logs that are not queried!!!!??
Another catch is: let's say some user has used the wild card search, which covers the majority of the log statements, but the user might not navigated crossing the first page of the paginated result. In this case, the ad hoc query might cover a large amount of log lines, but I want to consider only the first page log lines as viewed and not the log lines from the 2nd page.
What would be the best approach to get this detail? I could write a java program using the Splunk APIs but what parameters I should check for? Is there any attribute like last accessed or last viewed for each events? Do we have any unique IDs for each events that are logged?
... View more