Splunk Enterprise Security

Technology Add-on Default Index other than Main

aelliott
Motivator

I uploaded data into my system and created a TA that is CIM compliant.
I will be doing this for several sources, all that come from different indexes.
The issue I am having is that the queries in the app comes from several data models all that specify a sourcetype and no index, thus pulling from the default "main" index.
Is there a way to specify indexes to use for each type of add-on? or does anyone know a good solution to this issue?

0 Karma
1 Solution

aivarson_splunk
Splunk Employee
Splunk Employee

You could always change the access controls for which indexes get searched by default. You can do this either by role or by user. In Version 6 you go to Settings, Access Controls, Pick Users or Role (whichever you want to modify) then scroll down to Indexes searched by default and add the ones you need. If you want to add them all just add All non-internal indexes to searchable. Then you can run a search like this to verify that the indexes are being searched without having to specify them: * | stats values(index)

View solution in original post

aivarson_splunk
Splunk Employee
Splunk Employee

You could always change the access controls for which indexes get searched by default. You can do this either by role or by user. In Version 6 you go to Settings, Access Controls, Pick Users or Role (whichever you want to modify) then scroll down to Indexes searched by default and add the ones you need. If you want to add them all just add All non-internal indexes to searchable. Then you can run a search like this to verify that the indexes are being searched without having to specify them: * | stats values(index)

aelliott
Motivator

Thanks, I found this same answer and it worked! Here's my reference for anyone else wanting to do this.
http://docs.splunk.com/Documentation/ES/3.0/Install/ConfigureEnterpriseSecurity#Configure_multiple_i...

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...