Hi All,
Just wanted to get your feedback on the below issue we have right now with our new Splunk Cloud instance.
Unlike in enterprise version where you can assign the index to an app, we don't see the same option available in Splunk Cloud Version.
Does anyone know know how Apps to which index to search without defining it?
When you create new indexes, app column shows as 000-self-service and not the app we want to?
Thank you
Hi @zymeworks ,
the only way to assign an index to an app is to upload a custom app, containing te indexes.conf file.
Otherwise it isn't possible, but whay do you need this?
Ita relevant in on-premise installations because in this way you always know where's the indexes.conf file to manage it (eventually modifying it) or to port the app in another instance.
But in Splunk Cloud it isn't so relevant because you can modify the index only by GUI.
Ciao.
Giuseppe
Hi there,
Here are some workarounds:
1. Search by Index Name:
Instead of relying on the app, explicitly specify the index name in your searches. This ensures you query the desired data regardless of app association.
2. Leverage Tags:
Tag both indexes and apps with relevant keywords. Then, use the | where tag="app_tag" syntax in your searches to filter based on app association.
3. Utilize Search Macros:
Create macros that predefine the index name and relevant filters for each app. This streamlines search creation and avoids repetitive typing.
4. Consider Alerting & Dashboards:
For dashboards and alerts, you can set the index directly without relying on app association. This ensures they display data from the correct index.
5. Explore Custom Solutions:
If these workarounds don't suffice, consider developing custom scripts or tools to manage index-app relationships in Splunk Cloud.
Remember:
~ If the reply helps, a Karma upvote would be appreciated