Splunk search for Indexes Created by Users
Copy
index=_internal sourcetype=splunk_python action="handleCreate"
| stats latest(_time) as _time by loginUsername indexName
This search will return a table showing which users created which indexes in the time period searched.