<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index naming convention in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580484#M102413</link>
    <description>&lt;P&gt;Hi..&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. first best practice would be, as said on previous reply, to include source's name as part of index's name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe, if your company name is "test", you can name your indexes like, "test_windows", test_linux, test_firewall, etc&lt;/P&gt;&lt;P&gt;2. if you have a single splunk environment with dev/test/prod all under one splunk, then, you should have it like, .. dev_windows, test_windows, prod_windows, dev_firewall, dev_proxy, etc&lt;/P&gt;&lt;P&gt;3. how critical the logs are... maybe, you include that as part of the index. example, L1_windows, L2_windows, L3_windows&lt;/P&gt;&lt;P&gt;4. Application names can be included as part of index name... firwall_windows, wmi_windows, java_windows, etc..&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. business group names as part of index names.. ... sales_windows, custom_windows, etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it all depends on how you want to segregate your logs. hope you got some ideas, thanks.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jan 2022 16:31:10 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2022-01-10T16:31:10Z</dc:date>
    <item>
      <title>Index naming convention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580462#M102407</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is there a recommendation or a guideline available by Splunk on &lt;STRONG&gt;naming convention for INDEXES&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have a new Splunk Enterprise environment at my company with a plan of roughly 70 data sources to be onboarded one after the other.&lt;/P&gt;&lt;P&gt;For example the Windows TA has&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would be happy for each input i can get from you.&lt;/P&gt;&lt;P&gt;Thank you in advance,&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 15:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580462#M102407</guid>
      <dc:creator>ojay</dc:creator>
      <dc:date>2022-01-10T15:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Index naming convention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580469#M102409</link>
      <description>&lt;P&gt;It’s hard to say what is the best way to naming indexes (or other knowledge objects). You could found some examples from splunk documents.&lt;/P&gt;&lt;P&gt;Personally I prefer to use &amp;lt;source system name&amp;gt;_{audit,tech,apps} or similar suffix to separate security level of events. Then it depends how big your enterprise is, how many parts are in “source system name” to keep it unique in your installations including e.g. AD. Usually this leads to use abbreviations for those.&lt;/P&gt;&lt;P&gt;But I’m sure that there are almost as many ways than users/admins. But if/when you already have master data you should utilize it for naming all splunk KOs.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 15:11:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580469#M102409</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-10T15:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Index naming convention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580484#M102413</link>
      <description>&lt;P&gt;Hi..&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. first best practice would be, as said on previous reply, to include source's name as part of index's name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe, if your company name is "test", you can name your indexes like, "test_windows", test_linux, test_firewall, etc&lt;/P&gt;&lt;P&gt;2. if you have a single splunk environment with dev/test/prod all under one splunk, then, you should have it like, .. dev_windows, test_windows, prod_windows, dev_firewall, dev_proxy, etc&lt;/P&gt;&lt;P&gt;3. how critical the logs are... maybe, you include that as part of the index. example, L1_windows, L2_windows, L3_windows&lt;/P&gt;&lt;P&gt;4. Application names can be included as part of index name... firwall_windows, wmi_windows, java_windows, etc..&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. business group names as part of index names.. ... sales_windows, custom_windows, etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it all depends on how you want to segregate your logs. hope you got some ideas, thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 16:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580484#M102413</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2022-01-10T16:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Index naming convention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580486#M102414</link>
      <description>&lt;P&gt;Just don't keep any spaces rest I will leave it to your imagination&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 16:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/580486#M102414</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-10T16:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Index naming convention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/581900#M102544</link>
      <description>&lt;P&gt;Thanks everyone, i have decided to create something like&amp;nbsp;"technology_vendor"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jay&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 15:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-naming-convention/m-p/581900#M102544</guid>
      <dc:creator>ojay</dc:creator>
      <dc:date>2022-01-20T15:02:57Z</dc:date>
    </item>
  </channel>
</rss>

