<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create and configure new indexes in Splunk? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205281#M21554</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;

&lt;P&gt;My doubts are.&lt;BR /&gt;
(1) Need to create new Index in Splunk as we have source type, apps which can already be used to differentiate data into Splunk.&lt;BR /&gt;
(2) Where to configure the Indexes for Splunk as I can see Setting-&amp;gt;Indexes and create new index and assign with an app. So what is the next configuration that needs to be carried out with the index newly created?&lt;BR /&gt;
(3) Please help me if you have any document or artifact which can help me gain insight on Indexes from its reason for creation and configuring indexes please.&lt;/P&gt;

&lt;P&gt;Thanks a ton for making me understand the concept.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2016 12:46:51 GMT</pubDate>
    <dc:creator>vikram_m</dc:creator>
    <dc:date>2016-12-22T12:46:51Z</dc:date>
    <item>
      <title>How to create and configure new indexes in Splunk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205281#M21554</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;

&lt;P&gt;My doubts are.&lt;BR /&gt;
(1) Need to create new Index in Splunk as we have source type, apps which can already be used to differentiate data into Splunk.&lt;BR /&gt;
(2) Where to configure the Indexes for Splunk as I can see Setting-&amp;gt;Indexes and create new index and assign with an app. So what is the next configuration that needs to be carried out with the index newly created?&lt;BR /&gt;
(3) Please help me if you have any document or artifact which can help me gain insight on Indexes from its reason for creation and configuring indexes please.&lt;/P&gt;

&lt;P&gt;Thanks a ton for making me understand the concept.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 12:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205281#M21554</guid>
      <dc:creator>vikram_m</dc:creator>
      <dc:date>2016-12-22T12:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to create and configure new indexes in Splunk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205282#M21555</link>
      <description>&lt;P&gt;here is a splunk doc that might help:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Setupmultipleindexes"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Setupmultipleindexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 13:04:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205282#M21555</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2016-12-22T13:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to create and configure new indexes in Splunk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205283#M21556</link>
      <description>&lt;P&gt;Thanks cmerriman  this was very helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 13:24:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205283#M21556</guid>
      <dc:creator>vikram_m</dc:creator>
      <dc:date>2016-12-22T13:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to create and configure new indexes in Splunk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205284#M21557</link>
      <description>&lt;P&gt;Please pay attention to this section in the above link at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Setupmultipleindexes"&gt;Create custom indexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2269iEBA70CCA27F672BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;This hot portion of this index is called a bucket and we don't want excessive number of them. So, by following these rules we can avoid passing the 50K buckets per index, which is the best practice. &lt;/P&gt;

&lt;P&gt;Keep in mind also that the default of &lt;CODE&gt;maxHotSpanSecs&lt;/CODE&gt; is 86399 seconds, which is a day. For low indexing indexes it can produce lots of buckets, so for such indexes, we can change this value. &lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2016 02:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205284#M21557</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-12-25T02:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to create and configure new indexes in Splunk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205285#M21558</link>
      <description>&lt;P&gt;Thanks ddrillic  for the highlight.....I have read the pdf mentioned in the link.....got confidence about Indexes and its use in Splunk.&lt;/P&gt;

&lt;P&gt;Next action plan for me is to how do I assign particular host or source or sourcetype to my created custom Index.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 06:05:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-create-and-configure-new-indexes-in-Splunk/m-p/205285#M21558</guid>
      <dc:creator>vikram_m</dc:creator>
      <dc:date>2016-12-27T06:05:39Z</dc:date>
    </item>
  </channel>
</rss>

