Knowledge Management

How to get details regarding the deleted index?

vin02
Path Finder

One of the index(eg. index= test) has been deleted from the environment. which log i have to check for the respective details.

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion
0 Karma

adonio
Ultra Champion

alt text

0 Karma

adonio
Ultra Champion

try this:

index = _audit user=* action=indexes_edit
index = _internal  component=IndexWriter message="*Initializin*" component=IndexWriter | table _time idx 

Or this:

index = _audit user=* action=indexes_edit object=* | table user action object

hope it helps

0 Karma

vin02
Path Finder

Thanks for your response. but when i am adding my index name ,not getting any result

0 Karma

vin02
Path Finder

If my index name has been changed or deleted then how do i know?

0 Karma

adonio
Ultra Champion

Can you share how you are adding your index name in search?
I am attaching a screenshot on the answer below with an index i first created, then edited and then modified and then removed.
is it a single indexer? couple of them? indexer cluster?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...