Hi All,
I'd like to create a report that shows how often users are performing searches against indexes, or even sourcetypes. Is something like this possible? The goal here is to make sure the indexed data is actually being utilized, and not just sitting there in Splunk wasting license.
Thanks,
- Joe
hello jguzowski,
there are plenty of answers in this portal, here is a small sample:
https://answers.splunk.com/answers/273176/how-can-i-determine-how-much-an-index-is-being-sea.html
https://answers.splunk.com/answers/321581/how-to-find-the-most-searched-index-in-splunk.html
https://answers.splunk.com/answers/409198/how-to-check-the-most-accessedsearched-indexsource.html
the last link also checks for sourcetypes
hope it helps