Getting Data In

Search that lists the configured indexes on a Splunk indexer?

Derek
Path Finder

Hi,

Is there a search that can return the list of indexes configured on a Splunk Indexer?

Or is the only way to look at the _internal index and work it out based on data that exists in that index from performance metrics etc..

Thanks!

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You can run | eventcount summarize=false index=* index=_*. This search actually runs distributed, but it does add a field splunk_server so you can sort or filter on that.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

You can run | eventcount summarize=false index=* index=_*. This search actually runs distributed, but it does add a field splunk_server so you can sort or filter on that.

Simeon
Splunk Employee
Splunk Employee

If you have no more than 8 indexes, you can do the following:

index=_internal source=*metrics.log* per_index_thruput | stats count by series

The above search grabs indexing metrics from the internal logs. By default, Splunk will only track the top 10 indexes including the two internal ones (_internal and _audit). If you have more than 10 indexes, you can change the metrics logging limit.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...