Splunk Search

How to assign index of an app to another.

KarunK
Contributor

Hi,

I have an app called ngcdn and an index (we_accesslog_extsqu) for that app which is looking to a directory. Now i have created another app (cds) and my search on that app for the index="we_accesslog_extsqu" is not producing any results. From looking at the manager-> indexes, the index "we_accesslog_extsqu" is assigned/owned by ngcdn app.

How do I use the same index for my new app - "cds" ?
OR
How do i make the "we_accesslog_extsqu" index generic so that its is available to all apps ?

Thanks

Tags (2)
1 Solution

Takajian
Builder

I think the index="we_accesslog_extsqu" is defined in the app ngcdn. Did you share the index to others? From looking at the manager-> app -> sharing permissions is "global"? Your app will need to have global permission to share the configuration to other app.

View solution in original post

KarunK
Contributor

Thanks. It worked.

Takajian
Builder

I think the index="we_accesslog_extsqu" is defined in the app ngcdn. Did you share the index to others? From looking at the manager-> app -> sharing permissions is "global"? Your app will need to have global permission to share the configuration to other app.

bhawkins1
Communicator

As of splunk 6.5, the option to enable this is written as:

Sharing for config file-only objects

Set permissions for configurations that have been copied over or added to config files rather than created through the UI. Objects defined in config files only (not in the UI) should appear in

(Change the value from this app only (system) to All apps)

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...