All Apps and Add-ons

Can't Access Data From Non-Main Index Using Custom App (Sideview Utils)

RMartinezDTV
Path Finder

I feel like there is a simple answer to this question, but searching has failed me.

If I have a custom app (Sideview Utils in this case), how can I access data in indexes that aren't main? I have an index named XXX and the /manager/data/indexes webpage shows it is tied to the Search app. Similarly, my YYY index is tied to the Launcher app.

In the custom app, I can only retrieve data from the main index. Even if I search for *, the data is from the main index only.

What's the right way to allow the custom app access to data in XXX and YYY indexes? I don't see permissions on the index page.

1 Solution

ShaneNewman
Motivator

That is not really app specific, it is user specific.

Settings>Access Controls>Roles>Your Role>Indexes Searched by Default - Add "All non-internal indexes

Does that help?

View solution in original post

0 Karma

somesoni2
Revered Legend

As mentioned by ShaneNewman, Indexes are created on SPlunk instance and access is given by Role (ultimately user specific). What you have to do is to add indexes (XXX and YYY) to the role that your User Id is assigned.

Manager » Access controls » Roles » your role

In section "Indexes searched by default" and "Indexes", select the indexes XXX and YYY. and click on save. Log out and log in back and you're all set.

RMartinezDTV
Path Finder

Hm, this seems to work. I think the key was logging out and back in to get the changes to apply. I also learned a thing or two about the default Sideview Utils templates.

ShaneNewman
Motivator

That is not really app specific, it is user specific.

Settings>Access Controls>Roles>Your Role>Indexes Searched by Default - Add "All non-internal indexes

Does that help?

0 Karma

RMartinezDTV
Path Finder

Worked after I logged out and back in.
Thanks for helping me wrap my head around this.

RMartinezDTV
Path Finder

By complete coincidence, I just recently set that option to no avail. If this was the problem, then wouldn't I be able to do "index=XXX" in the Sideview Utils app's search anyway?

Can you (or someone) explain what the App field under Settings->Indexes refers to? Are indexes limited to the scope of their app?

My config files on the forwarder for XXX are in etc/apps/search so I can understand what happened there. Would moving the *.conf files have an effect?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...