All Apps and Add-ons

How do you set Cisco Add-on to a specific index?

wralph_EPACN
Explorer

I am looking at how to set a specific index for this add-on as we have multiple groups responsible for Cisco devices, and we do not want them to see each others logs.

Any idea how to do this?

0 Karma

lakshman239
SplunkTrust
SplunkTrust

create indexes.conf under etc/apps//local to have your index. Then in the inputs.conf, for that monitor stanza/syslog etc.. you can setup index and sourcetype.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...