Splunk Search

Does 5 automatically search all indexes?

cramasta
Builder

Did v5 change so that you automatically search against all indexes by default.

Before I would have to do a "index=custom sourcetype=foo" now I just do a "sourcetype=foo" and it works with out calling out the index. Pretty sure in 4.* the main index was only searched when not specifying a index.

Tags (1)
0 Karma
1 Solution

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

View solution in original post

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...