Splunk Search

Schedule search includes result from non-default index

daniel_splunk
Splunk Employee
Splunk Employee

From the document, if index=myindex was not mentioned, Splunk search will only use default indexes. However, I found that the behaviour is not true anymore. When I run a search, result return from non default index as well.

What is the possible cause?

Tags (1)
0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

You can check whether srchFilter is set in your role.

For example,

authorize.conf 
[default] 
srchFilter = NOT index=*_archive 

If you have set srchFilter to some value, it will get added to every search for this role.

As your srchFilter exist, it includes an “index=“ line and Splunk is not going to look at the srchIndexesDefault parameter.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...