Installation

Why is an index listed as "OTHER" when checking license usage?

N92
Path Finder

I am observing my license usage in which one index exist which name have "OTHER". Is it by default index or not. Which kind of information it contain? How can see it.

Labels (1)
0 Karma
1 Solution

DalJeanis
Legend

Depending on how you are looking at the usage, you may be using a command like timechart that lumps everything past the first few results -- 10, generally -- into an OTHER category.

See this one for discussion.

https://answers.splunk.com/answers/390253/how-to-search-the-list-of-hosts-in-the-other-categ.html

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @N92, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂

0 Karma

DalJeanis
Legend

Depending on how you are looking at the usage, you may be using a command like timechart that lumps everything past the first few results -- 10, generally -- into an OTHER category.

See this one for discussion.

https://answers.splunk.com/answers/390253/how-to-search-the-list-of-hosts-in-the-other-categ.html

inventsekar
SplunkTrust
SplunkTrust

main, _internal, _audit ---- these are the 3 indexes that comes defaultly with Splunk deployment.
the "OTHER" index must be created by the person who deployed your splunk.
Which kind of information it contain? --- you can simply look the events this index contain, or which hosts/sources/sourcetypes are there in this index, you can check the Deployment server config files as well

http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Aboutmanagingindexes

In addition to the main index, Splunk Enterprise comes preconfigured with a number of internal indexes. Internal indexes are named starting with an underscore (_). To see a full list of indexes in Splunk Web, click the Settings link in the upper portion of Splunk Web and then select Indexes. The list includes:

main: The default Splunk Enterprise index. All processed external data is stored here unless otherwise specified.
_internal: This index includes Splunk Enterprise internal logs and metrics.
_audit: Events from the file system change monitor, auditing, and all user search history.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...