WebOct 19, 2012 · You can get all kinds of info about your indexes by hitting the REST endpoint data/indexes: rest /services/data/indexes 20 Karma Reply sloshburch Splunk Employee 02-11-2013 11:13 AM Thank you for the rest command! I hadn't thought of … WebApr 9, 2024 · can only list hosts. if i do. metadata type=sourcetypes where index=*. can only list sourcetypes. if i do: index=* stats values (host) by sourcetype. the search is very slowly. I want the result:. fistTime Sourcetype Host lastTime recentTime totalCount 1522967692 nginx 192.168.1.2 152340603 1523243447 29125.
Splunk: List indexes and sources to which one has access
WebJun 30, 2015 · 06-30-2015 11:57 AM. You can try this: rest /services/authentication/users rename title as User, roles as Role stats count by User Role fields - count appendcols [ rest /services/authorization/roles table title srchIndexesAllowed rename title as Role] stats values (Role) as Role values (srchIndexesAllowed) as Indexes by User. 0 Karma. WebJan 27, 2024 · Solution. 01-27-2024 10:30 AM. You can use tstats command to get host and index data. metadata type=hosts eval age = now () - lastTime search host=* search age > 10 sort age d convert ctime (lastTime) fields age,host,lastTime appendcols [ tstats count where index="*" by host, index stats values (index) as indexes by host] If ... cody wy webcam live
How risk scores work in Splunk Enterprise Security
WebFeb 1, 2024 · You can use below search , given that your role has permission to search on _internal index, if this search doesn't work for you ask someone with admin role to run it. index=_internal source=*license_usage.log* type=Usage idx= eval GB=b/1024/1024/1024 stats sum (GB) by st 1 Karma Reply rakesh44 Communicator 02 … WebDear Experts.. Looking for help with a Splunk Query... I was working on a Splunk Query to identify the Frames connection to the HMC.. Im able to find the HMC's the frame is connected.. If a frame is connected with 2 hmc the active_hmc field will contain both hmc's separated by "_ " Incase the frame ... WebSep 21, 2024 · 1) How to list the indexes details available in splunk search heads? We can the indexes configured in splunk searched by login into splunk web portal --> settings --> indexes. By executing the splunk btool command from the search head instances to find the list of indexes available in splunk search head. calvin klein palla leather sandals