<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Unix and Linux with multiple indexes in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195801#M20253</link>
    <description>&lt;P&gt;So for Splunk App for Unix and Linux&lt;BR /&gt;
edit the macros.conf on the server&lt;BR /&gt;
change it to the following&lt;BR /&gt;
[os_index]&lt;BR /&gt;
definition = index=dev OR index=test OR index=live&lt;BR /&gt;
Create a dev,test and live index on the server&lt;/P&gt;

&lt;P&gt;The rest of the macros.conf then uses 'os_index'&lt;/P&gt;

&lt;P&gt;Then edit the inputs.conf on the forwarder for each environment thus Development will send it to the dev index.&lt;BR /&gt;
Now for the icing on the cake, set a role called dev with only access to the Dev index.  Lets see if this will work.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2014 15:47:37 GMT</pubDate>
    <dc:creator>BrendanMcE</dc:creator>
    <dc:date>2014-06-17T15:47:37Z</dc:date>
    <item>
      <title>Splunk App for Unix and Linux with multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195799#M20251</link>
      <description>&lt;P&gt;With Splunk App for Unix and Linux, it's is possible to state what indexes will be used.&lt;BR /&gt;
However is it possible to configure a splunk server that could connect to a number of environments dev,test,live each with the app on but using the splunkforwarder to send it to the central splunk but each of the environments use its own index.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2014 14:01:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195799#M20251</guid>
      <dc:creator>BrendanMcE</dc:creator>
      <dc:date>2014-06-11T14:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Unix and Linux with multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195800#M20252</link>
      <description>&lt;P&gt;Yes, however it might require you to edit some views.&lt;/P&gt;

&lt;P&gt;You should take a look at macros.conf to specify your indexes.&lt;BR /&gt;
example; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[all-indexes]
definition = index=dev OR index=test OR index=live

[dev-index]
definition = index=dev
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Call the macros using &lt;CODE&gt;all-indexes&lt;/CODE&gt; in savessearches.conf and edit the views that might contain hard-references to the "default" os index / search, grep for index=os .&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 11:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195800#M20252</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2014-06-17T11:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Unix and Linux with multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195801#M20253</link>
      <description>&lt;P&gt;So for Splunk App for Unix and Linux&lt;BR /&gt;
edit the macros.conf on the server&lt;BR /&gt;
change it to the following&lt;BR /&gt;
[os_index]&lt;BR /&gt;
definition = index=dev OR index=test OR index=live&lt;BR /&gt;
Create a dev,test and live index on the server&lt;/P&gt;

&lt;P&gt;The rest of the macros.conf then uses 'os_index'&lt;/P&gt;

&lt;P&gt;Then edit the inputs.conf on the forwarder for each environment thus Development will send it to the dev index.&lt;BR /&gt;
Now for the icing on the cake, set a role called dev with only access to the Dev index.  Lets see if this will work.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 15:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195801#M20253</guid>
      <dc:creator>BrendanMcE</dc:creator>
      <dc:date>2014-06-17T15:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Unix and Linux with multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195802#M20254</link>
      <description>&lt;P&gt;Thats sounds like it should work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 16:36:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-with-multiple-indexes/m-p/195802#M20254</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2014-06-17T16:36:31Z</dc:date>
    </item>
  </channel>
</rss>

