Hi Team,
Our Splunk is hosted in Cloud. And my requirement is that if an index is getting created then i need to get an alert and similarly if an index is getting deleted from the Search head i need to get an alert. So kindly help with the query.
Hi @anandhalagaras1,
this is the condition to identify index creation events:
index=_internal NOT StreamedSearch IndexWriter Initializing
For index deletion, you could use:
index=_internal NOT StreamedSearch event=removeIndex action=deleteIndexRequest
then in both cases, you can define the fields that you want to display.
Ciao.
Giuseppe