Deployment Architecture

How to create and configure new indexes in Splunk?

vikram_m
Path Finder

Hello team,

My doubts are.
(1) Need to create new Index in Splunk as we have source type, apps which can already be used to differentiate data into Splunk.
(2) Where to configure the Indexes for Splunk as I can see Setting->Indexes and create new index and assign with an app. So what is the next configuration that needs to be carried out with the index newly created?
(3) Please help me if you have any document or artifact which can help me gain insight on Indexes from its reason for creation and configuring indexes please.

Thanks a ton for making me understand the concept.

0 Karma
1 Solution

ddrillic
Ultra Champion

Please pay attention to this section in the above link at Create custom indexes

alt text

This hot portion of this index is called a bucket and we don't want excessive number of them. So, by following these rules we can avoid passing the 50K buckets per index, which is the best practice.

Keep in mind also that the default of maxHotSpanSecs is 86399 seconds, which is a day. For low indexing indexes it can produce lots of buckets, so for such indexes, we can change this value.

vikram_m
Path Finder

Thanks ddrillic for the highlight.....I have read the pdf mentioned in the link.....got confidence about Indexes and its use in Splunk.

Next action plan for me is to how do I assign particular host or source or sourcetype to my created custom Index.

0 Karma

cmerriman
Super Champion

vikram_m
Path Finder

Thanks cmerriman this was very helpful.

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...