Splunk Search

validate that index is not being queried in splunk

Path Finder

Good afternoon

   I can validate in the MC which index have events and which do not, but is it possible to know which index is not being consulted by users? this would let you know that data is not being used and possibly delete it.

Your support is appreciated

0 Karma


You can use the following as a base search, then examine the fields available to narrow down to what you're looking for.

index=_audit action=search sourcetype=audittrail
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!