All Apps and Add-ons

Splunk App for Windows Infrastructure: How to populate panels in the app from Windows data in custom indexes?

yannK
Splunk Employee
Splunk Employee

I have my windows data in custom indexes (windowze)

And the panels of the Windows infrastructure app 1.0.4 are not able to find them, and populate.
What is the best method to make them visible to my windows admin users ?

1 Solution

yannK
Splunk Employee
Splunk Employee

I found the role "windows-admin" defined in the app.

  1. Updated the list of indexes searched by default for the role "windows-admin" added "windowze"
  2. made my user inherit from the role "windows-admin"

Then I had an extra step in the windows app, update the macros

  1. go to settings > advanced search > macros in the windows app
  2. added the condition "OR index=windowze" to the necessary macros
  3. msad-index
  4. perfmon-index
  5. wineventlog-index

View solution in original post

jbernt_splunk
Splunk Employee
Splunk Employee

Adding the user to "winfra-admin" would be a better choice, since that is the role designed for the Windows Infrastructure app. 😉
Then alter the winfra-admin role to have the windowze index searched by default. That is why we designed our app this way, easier to use alternatively named indexes. Winfra-admin inherits from windows-admin, but as long as one of the two roles is used to search the other index by default, you should be good.

yannK
Splunk Employee
Splunk Employee

I found the role "windows-admin" defined in the app.

  1. Updated the list of indexes searched by default for the role "windows-admin" added "windowze"
  2. made my user inherit from the role "windows-admin"

Then I had an extra step in the windows app, update the macros

  1. go to settings > advanced search > macros in the windows app
  2. added the condition "OR index=windowze" to the necessary macros
  3. msad-index
  4. perfmon-index
  5. wineventlog-index
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...