The Indexes page

To view the Indexes page, select Settings > Indexes. The Indexes page lists the indexes in a Splunk Cloud Platform deployment and lets administrators create, update, delete, and modify the properties of indexes. To modify settings for an index, click its name.

From this page you can:

  • Create an index.
  • View index details such as the following.
    • Index name: The name specified when the index was created.
    • Index type: Whether the index is an events index or a metrics index.
    • App: The app to which the index belongs.
    • Current size: The approximate amount of uncompressed raw data currently stored in the index.
    • Max size: The maximum amount of uncompressed raw data (in TB, GB, or MB) that can be retained in the index.
    • Event count: The number of events in the index.
    • Earliest event: The time of the earliest event found in the index.
    • Latest event: The time of the most recent event found in the index.
    • Searchable Retention: The maximum age of events retained in the index.
    • Storage Type: The storage settings for expired data from a given index. Can be self storage, archive, or no additional storage.
    • Status: Enabled or disabled. Data in a disabled index is ignored in searches.
    • Delete an index. Caution: Deletes all data from an index and removes the index. The operation is final and can't be reversed.