如何在Splunk中查找全量仪表盘及使用信息并清理stale数据
Got it, let’s break this down into two clear tasks — cleaning up stale data and identifying unused dashboards. Here’s how to tackle each step by step:
First, we need to define what "stale" means for your use case (e.g., data not updated in 30+ days). Let’s start by identifying stale indexes or data segments:
Step 1: Identify Stale Indexes
Run this search to find the last time each index received new data:
| tstats latest(_time) as last_update where index=* by index | convert ctime(last_update) | eval days_since_update = round((now() - last_update)/86400, 1) | sort -days_since_update
This will show you all indexes sorted by how many days it’s been since their last update. Filter for indexes where days_since_update exceeds your threshold (e.g., 30).
Step 2: Remove Stale Data
Option A: Delete Entire Stale Indexes (Irreversible)
If an entire index is stale and no longer needed, use the Splunk CLI to remove it:
splunk remove index <your_stale_index_name>
Warning: This permanently deletes all data in the index, so double-check before running.
Option B: Delete Specific Stale Data Segments
If you only want to remove data older than a certain date (e.g., 90 days ago) from an index, use the delete command in a search:
index=<target_index> earliest=-1y@y latest=-90d@d | delete
Note: The delete command marks data for deletion (it won’t show up in searches), but physical deletion happens when Splunk runs its regular cleanup or when data reaches the frozen phase per your index retention policy.
Since you already have active usage logs from audit logs, we’ll compare that against the full list of dashboards to find the unused ones.
Step 1: Get the Full List of Dashboards
Run this REST API search to pull all dashboards across all apps:
| rest /servicesNS/-/-/data/ui/views | search isDashboard=1 | rename id as objectId | table objectId, title, eai:acl.app, eai:acl.owner
This gives you every dashboard’s unique ID, name, app, and owner.
Step 2: Get Active Dashboard Usage from Audit Logs
Extract the last time each dashboard was viewed from the _audit index:
| index=_audit action=view objectType=dashboard | stats latest(_time) as last_used by objectId | convert ctime(last_used)
This gives you a list of dashboards that have been accessed, along with their last usage timestamp.
Step 3: Compare to Find Unused Dashboards
Join the two datasets to identify dashboards with no usage records or usage older than your threshold (e.g., 90 days):
| rest /servicesNS/-/-/data/ui/views | search isDashboard=1 | rename id as objectId | table objectId, title, eai:acl.app, eai:acl.owner | leftjoin objectId [ | index=_audit action=view objectType=dashboard | stats latest(_time) as last_used by objectId ] | eval last_used = if(isnull(last_used), "Never Used", strftime(last_used, "%Y-%m-%d %H:%M:%S")) | where isnull(last_used) OR last_used < relative_time(now(), "-90d@d") | sort title
This output will show you all dashboards that either were never used or haven’t been accessed in the last 90 days.
Important Notes
- Audit Log Retention: If your
_auditindex only retains data for 90 days, you won’t see usage beyond that. If you need to check for longer periods, you might need to extend the_auditretention policy first. - Hidden Dashboards: The REST search includes all dashboards, including hidden ones. If you want to exclude hidden dashboards, add
| search isHidden=0to the REST search.
内容的提问来源于stack exchange,提问作者stuck

