<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566788#M9942</link>
    <description>&lt;P&gt;I think you asked similar question already - some two weeks ago or so.&lt;/P&gt;&lt;P&gt;Remember that not every search &lt;STRONG&gt;needs&lt;/STRONG&gt; a source index specification. You might do a | rest call. Or | makeresults. Or | ldapsearch. Or ...&lt;/P&gt;</description>
    <pubDate>Mon, 13 Sep 2021 07:15:26 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-09-13T07:15:26Z</dc:date>
    <item>
      <title>What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566756#M9935</link>
      <description>&lt;P&gt;Is there a security issue or problem if a saved search don't use index name for searching? Should all saved searches use index names for searching? Thank u very much in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 00:35:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566756#M9935</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-09-13T00:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566759#M9936</link>
      <description>&lt;P&gt;If you don't use an index statement, then your range of indexes searched will be at the whim of the administrator as to what indexes have been assigned as default indexes to the role the searching user is given.&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Security/Addandeditroles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Security/Addandeditroles&lt;/A&gt;&lt;/P&gt;&lt;P&gt;on searchable indexes.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 01:37:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566759#M9936</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-09-13T01:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566760#M9937</link>
      <description>&lt;P&gt;Thank u very much for this. Am not clear yet. Would you elaborate a bit. What problems are caused &amp;amp; what happens to the searches?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 03:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566760#M9937</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-09-13T03:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566773#M9939</link>
      <description>&lt;P&gt;Take for example this search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sourcetype=mysourcetype myfield=abc&lt;/LI-CODE&gt;&lt;P&gt;If your user role is configured to provide default indexes of 'main', then when you run a search without the index statement, you will ONLY search data from index=main. If your data exists in index=myindex then it will not be found&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 05:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566773#M9939</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-09-13T05:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566788#M9942</link>
      <description>&lt;P&gt;I think you asked similar question already - some two weeks ago or so.&lt;/P&gt;&lt;P&gt;Remember that not every search &lt;STRONG&gt;needs&lt;/STRONG&gt; a source index specification. You might do a | rest call. Or | makeresults. Or | ldapsearch. Or ...&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 07:15:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566788#M9942</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-13T07:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566795#M9945</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Shortly, i you don't define used index on savedsearches, you cannot know 100% sure which indexes are used (os should use) when user X have done search on time Y. Without index names, used index list has dynamically generated on time Y base on role(s) and &amp;nbsp;access by X. Of course you cannot see used indexes even you have defined those on SPL query from audit logs, but if/when you have version control on place for configuration, you can look it there.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 07:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566795#M9945</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-13T07:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566871#M9954</link>
      <description>&lt;P&gt;Happy Monday &amp;amp; thank u for your reply. Let's say you don't define index for user searching!! Are there default indexes assigned to each roles in Splunk? Thank u again.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 14:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566871#M9954</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-09-13T14:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566877#M9955</link>
      <description>&lt;P&gt;Thank u for your message. Would you share the full SPL for what you are teaching me please? Also is there a SPL to find what index is assigned to which search? Thank u again&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 14:59:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566877#M9955</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-09-13T14:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566879#M9956</link>
      <description>&lt;P&gt;In plain splunk installation there is usually at least main-index as default index for role user. Then this is inherited to other roles by including this role into other roles.&lt;/P&gt;&lt;P&gt;You can check this from Settings -&amp;gt; Role and then select role + 3. Indexes. That shows which index are granted directly or are inherited from other roles.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 15:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566879#M9956</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-13T15:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566881#M9957</link>
      <description>&lt;P&gt;You can start with this to see what user's has done.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_audit source=audittrail sourcetype=audittrail action=search 
| dedup user search
| table _time user search&lt;/LI-CODE&gt;&lt;P&gt;But remember that you can get information for only indexes which users have added to their SPL. If there are event types, macros or lookups used then you can see only those names and then you must look what those are and hope that those haven't changed after the SPL query has run.&lt;/P&gt;&lt;P&gt;As I said there is no way (or at least I haven't found it) to get real list of used indexes.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 15:13:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566881#M9957</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-13T15:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is wrong/issue if saved searches don't use index name for searching? Thank u for your time in advance.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566885#M9958</link>
      <description>&lt;P&gt;Happy Monday &amp;amp; thank u for your reply. Let's say you don't define index for user searching!! Are there default indexes assigned to each roles in Splunk? Thank u again.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 15:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-wrong-issue-if-saved-searches-don-t-use-index-name-for/m-p/566885#M9958</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-09-13T15:34:43Z</dc:date>
    </item>
  </channel>
</rss>

