Skip to main content
Splunk Lantern

Returning terms or indexed fields from event indexes with the Walklex command


As a Splunk administrator, you're responsible for managing and optimizing aspects of your Splunk deployment. You are interested in how Splunk handles event segmentation, and you are looking to optimize or improve event segmentation within your deployment. Your aim is to make searches faster and use less disk space.

Splunk uses tsidx (time series index) files to make data in your event indexes quicker to search. A tsidx file associates each unique keyword in your data with location references to events. You want to return a list of all of the terms or indexed fields from the tsidx files that comprise your event indexes.


You can use the walklex command to return a list of terms or indexed fields from your event indexes. The walklex command works on event indexes, as well as warm and cold buckets.

This video shows you:

  • How to work with the fields, field values, and terms returned by walklex
  • The conditions you'll need associated with your role in Splunk in order to run walklex
  • How to run the walklex command
  • How to interpret and work with results

Next steps

This article has been brought to you by Splunk Education. We’ve learned that the strongest superheroes up-skill with Splunk Education. That’s why we are making Splunk training easier and more accessible than ever with more than 20 self-paced, free eLearning courses. You can start with foundational courses like Intro to Splunk or dive into more advanced courses like Search Under the HoodResult Modification, and many more. Enroll today so you have the skills to detect the good, the bad, and the unproductive.

In addition, these Splunk resources might help you understand and implement this use case: