Thanks for this! This worked for me in 9.1.2. Definitely nicer than my thought of grepping for the index name recursively from all /opt/splunk/etc/apps/search and /opt/splunk/etc/users.
... View more
Yes, I used this query: | rest /services/apps/local splunk_server=* | search disabled=0 core=0 | fields title label version splunk_server | stats values(title) as title, values(label) as label, values(version) as version, by splunk_server disabled=0 is only listing the apps that are enabled (in use) core=0 is only listing the apps that are not Splunk core apps (part of the install pkg)
... View more