Hi,
Can you please help me to write a query to run on the search heads which will list me the index and app\workspace names in a tabular format?
It would be even helpful if you can write a query to display like these are the indexes in this App\Workspace.
This is basically to give an idea to a new user to get started.. If i can build a dashboard which will list out the list of indexes in each workspace it would help them to identify their workspace\app and indexes in it.
Thanks,
Thippesh
Hi yu94,
as admin user you can run this search:
| rest /servicesNS/-/-/data/indexes
| table title eai:acl.app
| rename "eai:acl.app" AS app title AS index
| stats count values(index) AS index by app
to get a table of indexes per app.
If you don't have the admin role assigned, ask your friendly Splunk admin to create a saved search and report/dashboard for you.
Hope this helps ...
cheers, MuS