Splunk Search

Does 5 automatically search all indexes?

cramasta
Builder

Did v5 change so that you automatically search against all indexes by default.

Before I would have to do a "index=custom sourcetype=foo" now I just do a "sourcetype=foo" and it works with out calling out the index. Pretty sure in 4.* the main index was only searched when not specifying a index.

Tags (1)
0 Karma
1 Solution

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

View solution in original post

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...