On the Data Utilization Element, users will see the Utilization Report that lists all Index Sourcetype pairings found in the Splunk environment.
The table provides columns to see how this data is currently being searched in three categories:
- Ad Hoc Queries
- This column shares the number of times this index and sourcetype have been included in an SPL search from a search box, by any user
- Scheduled Queries
- This column shows how often this index sourcetype pair is searched through Scheduled Searches
- Dashboard Queries
- This column reveals how often dashboards that contain panels that utilize the Index Sourcetype are used by users
After selecting an Index Sourcetype, the bottom half of the dashboard will populate with information related to how that particular Index Sourcetype is being utilized
Selecting a number value will reveal a table showcasing the Users, Searches, or Dashboards that utilize the data.
Scrolling further, a user can see what SPL was executed that had the Index Sourcetype in the search query.
By using these tools, admins can quickly know how data is being searched in their environment, and furthermore, by who.
Searches that do not have Sourcetypes in their SPL are not captured. Due to the speed improvements that Sourcetype defining brings, its recommended for Admins to popularize this search methodology as well!