All Apps and Add-ons

define index for my app

manikdham
Path Finder

i am creating a Splunk app. How do i define only a particular index to be used by the app. Only a particular index must be accessed from the app. where do i define the configurations.

Tags (4)

sdaniels
Splunk Employee
Splunk Employee

In inputs.conf you'll define the index you want for all of your inputs. In indexex.conf you will define where the index is stored.

[yourindex]
homePath = $SPLUNK_DB/yourindex/db
coldPath = $SPLUNK_DB/yourindex/colddb
thawedPath = $SPLUNK_DB/yourindex/thaweddb
maxTotalDataSizeMB = 10000

Then in all of your app searches and reports they will reference your index (start with index=yourindex). There is no way to assign an index to an app that i am aware of similar to how you can assign indexes to roles.

yulsplunkops
Engager

What about defining this on a Cloud Index you create ?   I get a defaut app assigned and there is no filed available to edit this.

Thanks

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You can put in comments underneath the answers rather than creating a new answer. You create the app, which is only going to have views and dashboards on your index. Then you will create a user role that only has access to that index and give those users access to your app as well.

0 Karma

manikdham
Path Finder

i want to configure app such that i listens to data from particular index. Objective is to provide users accessing app access data from particular index. what is the other way i can do this.

0 Karma

manikdham
Path Finder

in which file do i make the changes....

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

You can set this up by creating an index.conf in $SPLUNK_HOME/etc/apps//default and adding an index configuration there.

Brian

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...