Hi I afraid that currently there is no way to find answer to this question. There is no audit log which told if bucket has accessed (read event from it and returned it to search). We have asked this couple of years ago from Splunk Support, and then they put this feature on "future development list". Maybe it's time to create official request to https://ideas.splunk.com to get it? Currently you can find those queries which contains index name on SPL, but not other queries. Or at least I don' t know how it's possible. r. Ismo
... View more