Splunk Search

What are the issues with index naming?

the_wolverine
Champion

Previously we have encountered issues with using CAPS in index name configuration.

What other issues should we be aware of?

Are there issues with using special characters like "." or numerals in web2.0:

index=web2.0

0 Karma

yannK
Splunk Employee
Splunk Employee

yes, likely, use "underscore" to check.

index=web2_0

yannK
Splunk Employee
Splunk Employee

`******************************************************************************
PER INDEX OPTIONS
These options may be set under an [] entry.

Index names must consist of only numbers, letters, periods, underscores, and hyphens.
******************************************************************************`

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Yes...see this link (search for "PER INDEX OPTIONS")
http://docs.splunk.com/Documentation/Splunk/6.0.1/admin/Indexesconf

the_wolverine
Champion

Is this documented anywhere?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...