I want a query that shows the total volume of indexes used for splunk searches. Query on information that has to do with how much indexes are used based on splunk searches
Hello @whitecat001 try this :
index=_audit action="search" search="*" NOT user="splunk-system-user" savedsearch_name="" NOT search="\'|history*" NOT search="\'typeahead*"
| rex "index=(?P<myIndex>\w+)\s+\w+="
| stats count by myIndex