Getting Data In

Splunk api to get all the indexes from all the indexer masters from search head

sumandeb_git
New Member

Hi,
I want to know if there is an api to retrieve all the indexes from all the indexer masters from search head.
we have one LB--->SH clusters-->Many cluster Masters (indexer)-->Peer nodes associated with each cluster (indexer)

So I want a single API that can get me the indexes irrespective of from which cluster/nodes they exist.
Also in JSON format and unlimited pagination ( not default 30 but count=-1)

0 Karma

skalliger
SplunkTrust
SplunkTrust

Hi,

first of all, please don't refer to a Cluster Master as being an indexer. A CM basically is a Search Head. 🙂
If you're talking about "many indexers" I hope you actually mean "many indexer clusters (IDXC)" because otherwise, multiple CMs don't make any sense without those IDXC.

Here are three endpoints that you might find useful:

| rest /services/data/index-volumes
| rest /services/data/indexes
| rest /services/data/indexes-extended

Skalli

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...