Deployment Architecture

Why am I only getting results from the main index instead of all indexes when using the dbinspect command?

ltrand
Contributor

So, when I try to do a straight |dbinspect, I only get results for main instead of for all indexes. This is the same on the search head as it is on the index directly. Any thoughts on where I need to start to get the data? I'm trying to figure out better bucket rotation, but I can't do that unless I can evaluate the buckets.

Thanks everyone!

Tags (3)
0 Karma
1 Solution

MuS
Legend

Hi strand,

well the docs http://docs.splunk.com/Documentation/Splunk/6.3.1/SearchReference/Dbinspect are pretty straight forward on this:

index
Syntax: index=<string>
Description: Specify a name of an index to inspect. This option can be repeated for more indexes, and accepts wildcards such as asterisk ( * ) for all non-internal indexes.
Default: The default index, which is typically main.

If you want all available indexes to be shown, run this:

| dbinspect index=*

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi strand,

well the docs http://docs.splunk.com/Documentation/Splunk/6.3.1/SearchReference/Dbinspect are pretty straight forward on this:

index
Syntax: index=<string>
Description: Specify a name of an index to inspect. This option can be repeated for more indexes, and accepts wildcards such as asterisk ( * ) for all non-internal indexes.
Default: The default index, which is typically main.

If you want all available indexes to be shown, run this:

| dbinspect index=*

Hope this helps ...

cheers, MuS

ltrand
Contributor

Thanks for the clarification, I wasn't reading the documentation right on that.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...