Splunk search for Hot, warm and cold buckets by index
|dbinspect index=* | search index!=_* | eval state=case(state=="warm" OR state=="hot","hot/warm",1=1, state) | chart dc(bucketId) over index by state
This Splunk search will provide the total count of all buckets currently in your Splunk environment. The search sums hot and warm buckets together. The search will show the number of buckets separated out by index.