You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Splunk中查找全量仪表盘及使用信息并清理stale数据

Got it, let’s break this down into two clear tasks — cleaning up stale data and identifying unused dashboards. Here’s how to tackle each step by step:

1. Locate and Remove Stale Data in Splunk

First, we need to define what "stale" means for your use case (e.g., data not updated in 30+ days). Let’s start by identifying stale indexes or data segments:

Step 1: Identify Stale Indexes

Run this search to find the last time each index received new data:

| tstats latest(_time) as last_update where index=* by index
| convert ctime(last_update)
| eval days_since_update = round((now() - last_update)/86400, 1)
| sort -days_since_update

This will show you all indexes sorted by how many days it’s been since their last update. Filter for indexes where days_since_update exceeds your threshold (e.g., 30).

Step 2: Remove Stale Data

Option A: Delete Entire Stale Indexes (Irreversible)

If an entire index is stale and no longer needed, use the Splunk CLI to remove it:

splunk remove index <your_stale_index_name>

Warning: This permanently deletes all data in the index, so double-check before running.

Option B: Delete Specific Stale Data Segments

If you only want to remove data older than a certain date (e.g., 90 days ago) from an index, use the delete command in a search:

index=<target_index> earliest=-1y@y latest=-90d@d
| delete

Note: The delete command marks data for deletion (it won’t show up in searches), but physical deletion happens when Splunk runs its regular cleanup or when data reaches the frozen phase per your index retention policy.

2. Identify Unused Dashboards

Since you already have active usage logs from audit logs, we’ll compare that against the full list of dashboards to find the unused ones.

Step 1: Get the Full List of Dashboards

Run this REST API search to pull all dashboards across all apps:

| rest /servicesNS/-/-/data/ui/views
| search isDashboard=1
| rename id as objectId
| table objectId, title, eai:acl.app, eai:acl.owner

This gives you every dashboard’s unique ID, name, app, and owner.

Step 2: Get Active Dashboard Usage from Audit Logs

Extract the last time each dashboard was viewed from the _audit index:

| index=_audit action=view objectType=dashboard
| stats latest(_time) as last_used by objectId
| convert ctime(last_used)

This gives you a list of dashboards that have been accessed, along with their last usage timestamp.

Step 3: Compare to Find Unused Dashboards

Join the two datasets to identify dashboards with no usage records or usage older than your threshold (e.g., 90 days):

| rest /servicesNS/-/-/data/ui/views
| search isDashboard=1
| rename id as objectId
| table objectId, title, eai:acl.app, eai:acl.owner
| leftjoin objectId [
    | index=_audit action=view objectType=dashboard
    | stats latest(_time) as last_used by objectId
]
| eval last_used = if(isnull(last_used), "Never Used", strftime(last_used, "%Y-%m-%d %H:%M:%S"))
| where isnull(last_used) OR last_used < relative_time(now(), "-90d@d")
| sort title

This output will show you all dashboards that either were never used or haven’t been accessed in the last 90 days.

Important Notes

  • Audit Log Retention: If your _audit index only retains data for 90 days, you won’t see usage beyond that. If you need to check for longer periods, you might need to extend the _audit retention policy first.
  • Hidden Dashboards: The REST search includes all dashboards, including hidden ones. If you want to exclude hidden dashboards, add | search isHidden=0 to the REST search.

内容的提问来源于stack exchange,提问作者stuck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:15:18