<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to disable the main index? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233782#M23851</link>
    <description>&lt;P&gt;just specify &lt;CODE&gt;index=other&lt;/CODE&gt; to avoid pulling in the &lt;CODE&gt;Indexes searched by default&lt;/CODE&gt; setting (which contains &lt;CODE&gt;Index=main&lt;/CODE&gt;).&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2016 05:01:43 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2016-07-05T05:01:43Z</dc:date>
    <item>
      <title>Is it possible to disable the main index?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233778#M23847</link>
      <description>&lt;P&gt;When I try to disable main index in Splunk Enterprise it gives me the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;In handler 'indexes': cannot disable idx=main, is internal
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 29 Jun 2016 05:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233778#M23847</guid>
      <dc:creator>ronak1308</dc:creator>
      <dc:date>2016-06-29T05:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to disable the main index?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233779#M23848</link>
      <description>&lt;P&gt;Just remove &lt;CODE&gt;main&lt;/CODE&gt; from &lt;CODE&gt;Indexes searched by default&lt;/CODE&gt; and &lt;CODE&gt;Available search indexes&lt;/CODE&gt; from the &lt;CODE&gt;User&lt;/CODE&gt; role.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 20:28:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233779#M23848</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-07-04T20:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to disable the main index?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233780#M23849</link>
      <description>&lt;P&gt;For the learning purposes, may we know why you would like disable the main index, please.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 23:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233780#M23849</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2016-07-04T23:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to disable the main index?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233781#M23850</link>
      <description>&lt;P&gt;I want to disable main index because  my one application's data is being indexed in main index and other application's data in other index, so in order to test that we are getting same fields from both the applications I need to disable the indexes of one application and test the other. And moreover I can't delete any of the applications which would be the most easiest way to test.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 04:18:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233781#M23850</guid>
      <dc:creator>ronak1308</dc:creator>
      <dc:date>2016-07-05T04:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to disable the main index?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233782#M23851</link>
      <description>&lt;P&gt;just specify &lt;CODE&gt;index=other&lt;/CODE&gt; to avoid pulling in the &lt;CODE&gt;Indexes searched by default&lt;/CODE&gt; setting (which contains &lt;CODE&gt;Index=main&lt;/CODE&gt;).&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 05:01:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-it-possible-to-disable-the-main-index/m-p/233782#M23851</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-07-05T05:01:43Z</dc:date>
    </item>
  </channel>
</rss>

