<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: customized *NIX app for external users in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/customized-NIX-app-for-external-users/m-p/71422#M2469</link>
    <description>&lt;P&gt;Unfortunately version 4.6 and before of the *nix app is hard coded to index=os.  This is was a mistake.  To fix, you would have to copy unix/default/savedsearches.conf to unix/local/savedsearches.conf and change the references to index=os to the index where your data lives.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2013 15:16:22 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2013-03-22T15:16:22Z</dc:date>
    <item>
      <title>customized *NIX app for external users</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/customized-NIX-app-for-external-users/m-p/71421#M2468</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;since few days I&lt;CODE&gt;m trying to configure access to *NIX application to my external users.&lt;BR /&gt;
I&lt;/CODE&gt;m using that application to monitor my linux servers located in the cloud. To keep separate data for each group of the servers I created dedicated indexes and users. &lt;BR /&gt;
Each user have access only to his own index.&lt;/P&gt;

&lt;P&gt;Problem:&lt;BR /&gt;
I&lt;CODE&gt;m login with user "teama", I&lt;/CODE&gt;m clicking on *UNIX app. Next from the top menu I`m choosing:&lt;/P&gt;

&lt;P&gt;CPU -- &amp;gt; CPU by host&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://img26.imageshack.us/img26/9475/splunkcpumennu.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;And it seems that is not working. In index for that user I see CPU data. It seems that *UNIX app searching by default in "os" index. How to change it ? I need to setup for each user different default index. Maybe somebody could support me ?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://img9.imageshack.us/img9/3456/splunkcpumennu1.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 12:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/customized-NIX-app-for-external-users/m-p/71421#M2468</guid>
      <dc:creator>konradwawryn</dc:creator>
      <dc:date>2013-03-22T12:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: customized *NIX app for external users</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/customized-NIX-app-for-external-users/m-p/71422#M2469</link>
      <description>&lt;P&gt;Unfortunately version 4.6 and before of the *nix app is hard coded to index=os.  This is was a mistake.  To fix, you would have to copy unix/default/savedsearches.conf to unix/local/savedsearches.conf and change the references to index=os to the index where your data lives.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 15:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/customized-NIX-app-for-external-users/m-p/71422#M2469</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2013-03-22T15:16:22Z</dc:date>
    </item>
  </channel>
</rss>

