<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows App and multiple indexes in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11831#M46</link>
    <description>&lt;P&gt;Hello,
I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine.
However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??).
Does someone know how to do it?&lt;/P&gt;

&lt;P&gt;Thanks. &lt;/P&gt;</description>
    <pubDate>Tue, 20 Apr 2010 21:34:03 GMT</pubDate>
    <dc:creator>bulliarda</dc:creator>
    <dc:date>2010-04-20T21:34:03Z</dc:date>
    <item>
      <title>Windows App and multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11831#M46</link>
      <description>&lt;P&gt;Hello,
I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine.
However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??).
Does someone know how to do it?&lt;/P&gt;

&lt;P&gt;Thanks. &lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2010 21:34:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11831#M46</guid>
      <dc:creator>bulliarda</dc:creator>
      <dc:date>2010-04-20T21:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows App and multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11832#M47</link>
      <description>&lt;P&gt;The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2010 23:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11832#M47</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-20T23:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows App and multiple indexes</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11833#M48</link>
      <description>&lt;P&gt;Excellent it works.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2010 20:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-App-and-multiple-indexes/m-p/11833#M48</guid>
      <dc:creator>bulliarda</dc:creator>
      <dc:date>2010-04-23T20:55:23Z</dc:date>
    </item>
  </channel>
</rss>

