<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Windows Infrastructure default index issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543615#M90756</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30898"&gt;@token2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the easiest way is to do this by gui in [Settings -- Roles -- your_role -- indexes].&lt;/P&gt;&lt;P&gt;If you want to do this in .conf file, open: &lt;STRONG&gt;%SPLYNK_HOME/etc/system/local/authorize.conf&lt;/STRONG&gt; and in the stanza of you role add (if there isn't) or modify the option &lt;STRONG&gt;srchIndexesDefault&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: if this answer solves your need, please accept it fot the other people of Community or tell me how can I help you more (and Karma Points are apprecited &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Mar 2021 06:56:25 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-03-13T06:56:25Z</dc:date>
    <item>
      <title>Splunk App for Windows Infrastructure default index issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543467#M90738</link>
      <description>&lt;P&gt;I have the latest SA-LDAP, Splunk_TA_Windows and Windows Infra apps installed.&amp;nbsp; I have sourcetype WinHostMon data coming in, but the Infrastructure app guided setup says it is not detected.&lt;/P&gt;&lt;P&gt;I jumped over to one of the infra dashboards and all panels have "No results found" &amp;gt;&amp;gt; Host Monitoring - Operations &amp;gt;&amp;gt; Disk Free Space Distribution and opened that in search.&amp;nbsp; By simply inputting index=windows the search then works.&lt;/P&gt;&lt;P&gt;Where does the app designate the default index it's searches refer to?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 01:46:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543467#M90738</guid>
      <dc:creator>token2</dc:creator>
      <dc:date>2021-03-12T01:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure default index issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543496#M90741</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30898"&gt;@token2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first see if you have logs in the indexes where logs are stored:&amp;nbsp;If you haven't results, there's a problem in log ingestion.&lt;/P&gt;&lt;P&gt;If instead you have results, open a search of one panel in Search, then add &lt;EM&gt;index="win*"&lt;/EM&gt; to the main search and see if you have results: probably the indexes where logs are stored isn't in the default search path.&lt;/P&gt;&lt;P&gt;If this is the problem you have two choices:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;add those indexes to the default path for the roles you're using,&lt;/LI&gt;&lt;LI&gt;modify all the eventtypes adding the indexes.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;First solution is quicher to resolve but I don't like because your searches are slower.&lt;/P&gt;&lt;P&gt;I prefer the second solution even if is longer to implement but is more performant.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 07:44:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543496#M90741</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-12T07:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure default index issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543602#M90753</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;I get results if I input index=win* (in this case its index=windows).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How does one go about changing the default path for the role via .conf files?&amp;nbsp; I see it in the GUI:&lt;/P&gt;&lt;P&gt;Settings &amp;gt;&amp;gt; Authentication Methods (because using LDAP in this case) &amp;gt;&amp;gt; LDAP Settings &amp;gt;&amp;gt; Map groups &amp;gt;&amp;gt; Edit LDAP group name user is affected by, added "winfra-admin".&lt;/P&gt;&lt;P&gt;Where is this found inside of the Splunk file system?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 23:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543602#M90753</guid>
      <dc:creator>token2</dc:creator>
      <dc:date>2021-03-12T23:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure default index issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543615#M90756</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30898"&gt;@token2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the easiest way is to do this by gui in [Settings -- Roles -- your_role -- indexes].&lt;/P&gt;&lt;P&gt;If you want to do this in .conf file, open: &lt;STRONG&gt;%SPLYNK_HOME/etc/system/local/authorize.conf&lt;/STRONG&gt; and in the stanza of you role add (if there isn't) or modify the option &lt;STRONG&gt;srchIndexesDefault&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: if this answer solves your need, please accept it fot the other people of Community or tell me how can I help you more (and Karma Points are apprecited &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 06:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Windows-Infrastructure-default-index-issue/m-p/543615#M90756</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-13T06:56:25Z</dc:date>
    </item>
  </channel>
</rss>

