Ad slot: top

SPL

List of Indexes

Description

Submitted by ItsJohnLocke

This simple Splunk query will return results for indexes that the current user (typically you) have access to: *NOTE* depending on settings this may or may not return internal indexes.
15 27
host=* | dedup index |table index

Comments

8 total

MA
masdeeper
3/8/2018

This is resource consumming. REST or tstats would be a better choice.

BR
Brian
4/20/2020

| tstats values(sourcetype) where index=* by index

IG
igor
11/17/2020

I prefer something like this\r\n\r\n| eventcount summarize=f index=* index=_* | dedup index | fields index

DP
dpl
12/29/2020

Your query is going to be slow. Your better off using dbinspect\r\n\r\n| dbinspect index=* | stats count by index

BL
blabli
5/19/2021

| rest splunk_server=* /services/data/indexes \r\n| fields title \r\n| dedup title

JR
JR
2/28/2022

Here is my SPL\r\n| eventcount summarize=f index=* index=_* | dedup index | fields index | sort index

K.
K.T.
7/28/2022

This one was the only one to aggregate the source type by the index in the clearest manner. Thanks

SE
Sebastian Rauhala
3/14/2023

tstats is also a good option. \r\n\r\n| tstats latest(_time) as _time count where index=* OR index_* earliest=-24h latest=now by index, sourcetype, source, host

Leave a comment

You must log in to post a comment.

Ad slot: bottom