List of Indexes ItsJohnLocke 8 Comments Vote Up +15 Vote Down -27You already voted! This simple Splunk query will return results for indexes that the current user (typically you) have access to: *NOTE* depending on settings this may or may not return internal indexes. host=* | dedup index |table index Share This: Tagged: indexes
This is resource consumming. REST or tstats would be a better choice.
| tstats values(sourcetype) where index=* by index
This one was the only one to aggregate the source type by the index in the clearest manner. Thanks
I prefer something like this
| eventcount summarize=f index=* index=_* | dedup index | fields index
Your query is going to be slow. Your better off using dbinspect
| dbinspect index=* | stats count by index
| rest splunk_server=* /services/data/indexes
| fields title
| dedup title
Here is my SPL
| eventcount summarize=f index=* index=_* | dedup index | fields index | sort index
tstats is also a good option.
| tstats latest(_time) as _time count where index=* OR index_* earliest=-24h latest=now by index, sourcetype, source, host