Splunk · Schema
Index
AnalyticsData AnalysisLoggingMachine DataMonitoringObservabilityPlatformSecuritySIEM
Properties
| Name | Type | Description |
|---|---|---|
| name | string | The index name |
| content | object |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "#/components/schemas/Index",
"title": "Index",
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "The index name",
"example": "Example Title"
},
"content": {
"type": "object",
"properties": {
"datatype": {
"type": "string",
"description": "The type of data stored in the index",
"enum": [
"event",
"metric"
]
},
"totalEventCount": {
"type": "integer",
"description": "Total number of events in the index"
},
"currentDBSizeMB": {
"type": "integer",
"description": "Current database size in megabytes"
},
"maxDataSize": {
"type": "string",
"description": "Maximum size of a hot bucket",
"enum": [
"auto",
"auto_high_volume"
],
"default": "auto"
},
"maxTotalDataSizeMB": {
"type": "integer",
"description": "Maximum total size of the index in MB",
"default": 500000
},
"maxHotBuckets": {
"type": "integer",
"description": "Maximum number of hot buckets for the index",
"default": 3
},
"maxWarmDBCount": {
"type": "integer",
"description": "Maximum number of warm buckets",
"default": 300
},
"frozenTimePeriodInSecs": {
"type": "integer",
"description": "Number of seconds after which data is frozen (archived or deleted). Default is 188697600 (6 years).",
"default": 188697600
},
"homePath": {
"type": "string",
"description": "Path for hot and warm buckets"
},
"coldPath": {
"type": "string",
"description": "Path for cold buckets"
},
"thawedPath": {
"type": "string",
"description": "Path for thawed (restored) buckets"
},
"disabled": {
"type": "boolean",
"description": "Whether the index is disabled"
},
"isInternal": {
"type": "boolean",
"description": "Whether this is an internal Splunk index"
},
"minTime": {
"type": "string",
"description": "Earliest time of data in the index"
},
"maxTime": {
"type": "string",
"description": "Latest time of data in the index"
},
"repFactor": {
"type": "string",
"description": "Replication factor for clustered environments"
},
"enableOnlineBucketRepair": {
"type": "boolean"
},
"quarantinePastSecs": {
"type": "integer",
"description": "Events with timestamps this many seconds in the past are quarantined"
},
"quarantineFutureSecs": {
"type": "integer",
"description": "Events with timestamps this many seconds in the future are quarantined"
}
},
"example": "example_value"
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/splunk-index"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.