Indexes
Query the data indexes in Splunk, including indexes shared across all search peers.
Columns
| Name | Type | Description |
| Title [KEY] | String | The name of the index. |
| SplunkServer [KEY] | String | The Splunk server that hosts the index. |
| Id | String | The REST resource link for the index. |
| UpdatedAt | Datetime | Datetime of the last update of the index. |
| Published | Datetime | Datetime when the index entry was published. |
| Author | String | The Splunk user that owns the index entry. |
| App | String | The Splunk app where the index is shared. |
| CanList | Boolean | Indicates whether the index can be listed by the user. |
| CanWrite | Boolean | Indicates whether the index can be modified by the user. |
| Modifiable | Boolean | Indicates whether the index can be modified. |
| Owner | String | The Splunk user that owns the index. |
| ReadPermissions | String | Permissions to read this index. |
| WritePermissions | String | Permissions to write to this index. |
| Removable | Boolean | Indicates whether the index can be removed. |
| Sharing | String | The index sharing type. |
| AssureUTF8 | Boolean | Indicates whether all data retrieved from the index is proper UTF-8. |
| BucketMergeMaxMergeSizeMB | Integer | The maximum size, in MB, of the merged bucket produced by bucket merging. |
| BucketMergeMaxMergeTimeSpanSecs | Integer | The maximum time span, in seconds, of the merged bucket produced by bucket merging. |
| BucketMergeMinMergeSizeMB | Integer | The minimum size, in MB, of the merged bucket produced by bucket merging. |
| BucketMerging | Boolean | Indicates whether bucket merging is enabled for the index. |
| BucketRebuildMemoryHint | String | Suggestion for the bucket rebuild process for the size of the time-series (tsidx) file to make. |
| ColdPath | String | Filepath to the cold databases for the index. |
| ColdPathMaxDataSizeMB | Integer | The maximum size, in MB, that the cold database can reach before the oldest data is frozen. |
| ColdPathExpanded | String | Absolute filepath to the cold databases. |
| ColdToFrozenDir | String | Destination path for the frozen archive. Use as an alternative to ColdToFrozenScript. |
| ColdToFrozenScript | String | Path to the archiving script. |
| CompressRawdata | Boolean | Indicates whether the raw data is compressed. |
| CurrentDBSizeMB | Integer | Total size, in MB, of data stored in the index. The total includes data in the home, cold, and thawed paths. |
| DataType | String | The type of index. |
| DefaultDatabase | String | If no index destination information is available in the input data, this index is the destination of such data. |
| Disabled | Boolean | Indicates whether the index is disabled. |
| EnableDataIntegrityControl | Boolean | Indicates whether data integrity control is enabled for the index. |
| EnableOnlineBucketRepair | Boolean | Indicates whether asynchronous online bucket repair is enabled. |
| EnableRealtimeSearch | Boolean | Indicates whether real-time search is enabled for the index. |
| EnableTsidxReduction | Boolean | Indicates whether tsidx reduction is enabled for the index. |
| FederatedDataset | String | The federated dataset associated with the index. |
| FederatedProvider | String | The federated provider associated with the index. |
| FileSystemExecutorWorkers | Integer | The number of threads used for file system operations on the index. |
| FrozenTimePeriodInSecs | Integer | Number of seconds after which indexed data rolls to frozen. |
| HomePath | String | An absolute path that contains the hot and warm buckets for the index. |
| HomePathMaxDataSizeMB | Integer | The maximum size, in MB, that the hot and warm databases can reach before the oldest data is moved to cold. |
| HomePathExpanded | String | An absolute filepath to the hot and warm buckets for the index. |
| HotBucketStreamingDeleteHotsAfterRestart | Boolean | Indicates whether hot buckets are deleted after a restart when hot bucket streaming is enabled. |
| HotBucketStreamingExtraBucketBuildingCmdlineArgs | String | Extra command line arguments used when building buckets for hot bucket streaming. |
| HotBucketStreamingRemoveRemoteSlicesOnRoll | Boolean | Indicates whether remote slices are removed when a bucket rolls. |
| HotBucketStreamingReportStatus | String | The reporting status of hot bucket streaming. |
| HotBucketStreamingSendSlices | Boolean | Indicates whether slices are sent for hot bucket streaming. |
| HotBucketTimeRefreshInterval | Integer | The interval, in seconds, at which the hot bucket time is refreshed. |
| IndexThreads | String | Number of threads used for indexing. |
| IsInternal | Boolean | Indicates whether this is an internal index. |
| IsReady | Boolean | Indicates whether the index is properly initialized. |
| IsVirtual | Boolean | Indicates whether the index is virtual. |
| JournalCompression | String | The compression algorithm used for the rawdata journal of the index. |
| LastInitSequenceNumber | Integer | The sequence number of the last index processor initialization. |
| LastInitTime | Datetime | Last time the index processor was successfully initialized. |
| MaxBloomBackfillBucketAge | String | If a warm or cold bucket is older than this, the bloomfilter is not created or rebuilt. |
| MaxBucketSizeCacheEntries | Integer | The maximum number of bucket size cache entries. |
| MaxConcurrentOptimizes | Integer | The number of concurrent optimize processes that can run against a hot bucket. |
| MaxDataSize | String | The maximum size, in MB, for a hot DB to reach before a roll to warm is triggered. |
| MaxGlobalDataSizeMB | Integer | The maximum size, in MB, for the global (clustered) data of the index. |
| MaxGlobalRawDataSizeMB | Integer | The maximum size, in MB, for the global (clustered) raw data of the index. |
| MaxHotBuckets | String | Maximum hot buckets that can exist per index. |
| MaxHotIdleSecs | Integer | Maximum life, in seconds, of a hot bucket. |
| MaxHotSpanSecs | Integer | Upper bound of target maximum timespan of hot/warm buckets in seconds. |
| MaxMemMB | Integer | The amount of memory, in MB, to allocate for buffering a single tsidx file into memory before flushing to disk. |
| MaxMetaEntries | Integer | Sets the maximum number of unique lines in data files in a bucket. |
| MaxRunningProcessGroups | String | The maximum number of running process groups for the index. |
| MaxRunningProcessGroupsLowPriority | Integer | The maximum number of low priority running process groups for the index. |
| MaxTime | Datetime | ISO8601 timestamp of the newest event time in the index. |
| MaxTimeUnreplicatedNoAcks | Integer | Upper limit, in seconds, on how long an event can sit in raw slice. Applies only if replication is enabled. |
| MaxTimeUnreplicatedWithAcks | Integer | Upper limit, in seconds, on how long events can sit unacknowledged in a raw slice. |
| MaxTotalDataSizeMB | Integer | The maximum size of an index, in MB. If an index grows larger, the oldest data is frozen. |
| MaxWarmDBCount | String | The maximum number of warm buckets. |
| MemPoolMB | String | Determines how much memory is given to the indexer memory pool. |
| MetricCompressionBlockSize | Integer | The compression block size for metric indexes. |
| MetricEnableFloatingPointCompression | Boolean | Indicates whether floating point compression is enabled for metric indexes. |
| MetricMaxHotBuckets | String | The maximum number of hot buckets for metric indexes. |
| MetricSplitByIndexKeys | String | The index keys used to split metric data. |
| MetricStubOutRawdataJournal | Boolean | Indicates whether the rawdata journal is stubbed out for metric indexes. |
| MetricTimestampResolution | String | The timestamp resolution for metric indexes. |
| MetricTsidxTargetSizeMB | Integer | The target size, in MB, of tsidx files for metric indexes. |
| MinHotIdleSecsBeforeForceRoll | String | Minimum idle seconds before a hot bucket is force-rolled. |
| MinRawFileSyncSecs | String | Sets how frequently splunkd forces a filesystem sync while compressing journal slices. |
| MinStreamGroupQueueSize | Integer | Minimum size of the queue that stores events in memory before committing them to a tsidx file. |
| MinTime | Datetime | ISO8601 timestamp of the oldest event time in the index. |
| PartialServiceMetaPeriod | Integer | Enables metadata sync every specified number of seconds, for records that can be synced in place. |
| ProcessTrackerServiceInterval | Integer | How often, in seconds, the indexer checks the status of the child OS processes it launched. |
| QuarantineFutureSecs | Integer | Events with a timestamp this many seconds newer than now are dropped into the quarantine bucket. |
| QuarantinePastSecs | Integer | Events with a timestamp this many seconds older than now are dropped into the quarantine bucket. |
| RawChunkSizeBytes | Integer | Target uncompressed size, in bytes, for individual raw slice in the rawdata journal of the index. |
| RepFactor | String | Index replication control. Applies to only clustering peers. |
| RotatePeriodInSecs | Integer | How frequently, in seconds, to check if a new hot bucket needs to be created. |
| RtRouterQueueSize | Integer | The queue size for the real-time router of the index. |
| RtRouterThreads | Integer | The number of threads used by the real-time router of the index. |
| SelfStorageThreads | Integer | The number of threads used for self storage of the index. |
| ServiceInactiveIndexesPeriod | Integer | How frequently, in seconds, inactive indexes are serviced. |
| ServiceMetaPeriod | Integer | Defines how frequently metadata is synced to disk, in seconds. |
| ServiceOnlyAsNeeded | Boolean | Indicates whether the index is serviced only as needed. |
| ServiceSubtaskTimingPeriod | Integer | The timing period, in seconds, for index service subtasks. |
| SplitByIndexKeys | String | The index keys used to split data. |
| StreamingTargetTsidxSyncPeriodMsec | Integer | The sync period, in milliseconds, for the streaming target tsidx. |
| SummaryHomePathExpanded | String | Absolute filepath to the summary home databases. |
| SuppressBannerList | String | List of indexes for which the 'index missing' warning banner messages are suppressed. |
| SuspendHotRollByDeleteQuery | Boolean | Indicates whether hot bucket rolling is suspended by a delete query. |
| Sync | String | Specifies the number of events that trigger the indexer to sync events. |
| SyncMeta | Boolean | Indicates whether a sync operation is called before the file descriptor is closed on metadata file updates. |
| ThawedPath | String | An absolute path that contains the thawed (resurrected) databases for the index. |
| ThawedPathExpanded | String | Absolute filepath to the thawed (resurrected) databases. |
| ThrottleCheckPeriod | Integer | Defines how frequently, in seconds, Splunk software checks for an index throttling condition. |
| TimePeriodInSecBeforeTsidxReduction | Integer | The amount of time, in seconds, that a bucket can age before tsidx reduction occurs. |
| TotalEventCount | Long | Total number of events in the index. |
| TsidxDedupPostingsListMaxTermsLimit | Integer | The maximum number of terms kept inside an in-memory hash table that improves tsidx compression. |
| TsidxReductionCheckPeriodInSec | Integer | How frequently, in seconds, to check whether tsidx reduction should occur. |
| TsidxTargetSizeMB | Integer | The target size, in MB, of tsidx files. |
| TsidxWritingLevel | Integer | The tsidx writing level used by the index. |
| TstatsHomePath | String | Location to store data model acceleration tsidx data for this index. |
| TstatsHomePathExpanded | String | Absolute filepath to the data model acceleration tsidx data for this index. |
| WaitPeriodInSecsForManifestWrite | Integer | The amount of time, in seconds, to wait for a manifest write. |
| WarmToColdScript | String | Path to a script to run when moving data from warm to cold. |