Splunk Search

Does 5 automatically search all indexes?

cramasta
Builder

Did v5 change so that you automatically search against all indexes by default.

Before I would have to do a "index=custom sourcetype=foo" now I just do a "sourcetype=foo" and it works with out calling out the index. Pretty sure in 4.* the main index was only searched when not specifying a index.

Tags (1)
0 Karma
1 Solution

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

View solution in original post

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...