Splunk Search

Does 5 automatically search all indexes?

cramasta
Builder

Did v5 change so that you automatically search against all indexes by default.

Before I would have to do a "index=custom sourcetype=foo" now I just do a "sourcetype=foo" and it works with out calling out the index. Pretty sure in 4.* the main index was only searched when not specifying a index.

Tags (1)
0 Karma
1 Solution

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

View solution in original post

gfrjonp
Explorer

Under the Manager -> Access controls -> Roles (Pick one like admin) you can specify what indexes are searched by default.
I have specifically set mine to "all non-internal indexes" this searches everything by default. Other roles only search the pertinent indexes.

*Edit: To answer your real question, no v5 didn't change. My fresh install still only shows main as the default searched index. I tested build 140868.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...