<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Has the &amp;quot;main&amp;quot; index been replaced by &amp;quot;default&amp;quot; since Splunk 6.3? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210205#M13156</link>
    <description>&lt;P&gt;Thanks,  I did install the Unix add on and app.  However my split license usage does not show main anymore.  It only shows default ,  os   and one other that I created.  Definitely new behavior since my upgrade.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2016 13:51:58 GMT</pubDate>
    <dc:creator>jackpal</dc:creator>
    <dc:date>2016-02-22T13:51:58Z</dc:date>
    <item>
      <title>Has the "main" index been replaced by "default" since Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210203#M13154</link>
      <description>&lt;P&gt;It seems that since my upgrade to Splunk 6.3 from 6.1, a new index called "default" has appeared.  Also, since then, my license usage has increased.  I am not sure if they are related.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 12:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210203#M13154</guid>
      <dc:creator>jackpal</dc:creator>
      <dc:date>2016-02-22T12:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Has the "main" index been replaced by "default" since Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210204#M13155</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I can only speak for myself, but in 6.3.1 the main index is still present and there's no "default" index.&lt;/P&gt;

&lt;P&gt;Maybe you installed an TA that created that index?&lt;/P&gt;

&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 13:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210204#M13155</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2016-02-22T13:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Has the "main" index been replaced by "default" since Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210205#M13156</link>
      <description>&lt;P&gt;Thanks,  I did install the Unix add on and app.  However my split license usage does not show main anymore.  It only shows default ,  os   and one other that I created.  Definitely new behavior since my upgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 13:51:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210205#M13156</guid>
      <dc:creator>jackpal</dc:creator>
      <dc:date>2016-02-22T13:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Has the "main" index been replaced by "default" since Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210206#M13157</link>
      <description>&lt;P&gt;I have the Splunk_TA_nix as well, thats not it.&lt;/P&gt;

&lt;P&gt;Try to have a look inside the indexes.conf. Maybe you can see something there about the main index. It should be in there.&lt;/P&gt;

&lt;P&gt;SPLUNK_HOME/etc/system/default( or local)/indexes.conf&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210206#M13157</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2020-09-29T08:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Has the "main" index been replaced by "default" since Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210207#M13158</link>
      <description>&lt;P&gt;main is still in there as a definition bu the path is: homePath   = $SPLUNK_DB/defaultdb/db  &lt;/P&gt;

&lt;P&gt;Not really sure what it was called before or if it was always called this.  I do know that main was always the "default" index&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 14:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210207#M13158</guid>
      <dc:creator>jackpal</dc:creator>
      <dc:date>2016-02-22T14:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Has the "main" index been replaced by "default" since Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210208#M13159</link>
      <description>&lt;P&gt;Thats mine, should be the default:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[main]
    homePath   = $SPLUNK_DB/defaultdb/db
    coldPath   = $SPLUNK_DB/defaultdb/colddb
    thawedPath = $SPLUNK_DB/defaultdb/thaweddb
    tstatsHomePath = volume:_splunk_summaries/defaultdb/datamodel_summary
    maxMemMB = 20
    maxConcurrentOptimizes = 6
    maxHotIdleSecs = 86400
    maxHotBuckets = 10
    maxDataSize = auto_high_volume
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 22 Feb 2016 14:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Has-the-quot-main-quot-index-been-replaced-by-quot-default-quot/m-p/210208#M13159</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2016-02-22T14:16:25Z</dc:date>
    </item>
  </channel>
</rss>

