<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What indexes are included in search by default? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57378#M14005</link>
    <description>&lt;P&gt;Great thanks, I checked the index for any settings but didn't think of the role.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2010 02:52:06 GMT</pubDate>
    <dc:creator>dswanson99</dc:creator>
    <dc:date>2010-09-24T02:52:06Z</dc:date>
    <item>
      <title>What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57376#M14003</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I was in the process of changing the index that certain events write to and came across a problem with a query I was using to verify the results.&lt;/P&gt;

&lt;P&gt;This input source appears in 3 different indices right now (os, main and access).&lt;/P&gt;

&lt;P&gt;If I search for  that appears in all of them WITHOUT an index qualifier I get data from 2 of the 3 indices.  If I add &lt;CODE&gt;index=*&lt;/CODE&gt; to the search then it finds all three indices.&lt;/P&gt;

&lt;P&gt;How is splunk deciding what indices to include (or exclude) by default?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 02:20:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57376#M14003</guid>
      <dc:creator>dswanson99</dc:creator>
      <dc:date>2010-09-24T02:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57377#M14004</link>
      <description>&lt;P&gt;You'll see events from those indexes without explicitly specifying one or more indexes in the search, that are selected as default indexes for your role(s). You can see/change this under Manager » Access controls » Roles » Some Role » Default indexes&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 02:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57377#M14004</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2010-09-24T02:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57378#M14005</link>
      <description>&lt;P&gt;Great thanks, I checked the index for any settings but didn't think of the role.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 02:52:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57378#M14005</guid>
      <dc:creator>dswanson99</dc:creator>
      <dc:date>2010-09-24T02:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57379#M14006</link>
      <description>&lt;P&gt;I can't see the Manager option in my splunk. We are using splunk 6.6.  My splunk looks like: &lt;A href="https://imgur.com/VxuOzxH"&gt;https://imgur.com/VxuOzxH&lt;/A&gt; . I don't see the Manager-&amp;gt; Access controls -&amp;gt;...&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jun 2018 18:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57379#M14006</guid>
      <dc:creator>kimberlytrayson</dc:creator>
      <dc:date>2018-06-16T18:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57380#M14007</link>
      <description>&lt;P&gt;Should be under "Settings" -&amp;gt; "Access Controls". I guess that changed somewhere in the last ~8 years &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jun 2018 18:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57380#M14007</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-16T18:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57381#M14008</link>
      <description>&lt;P&gt;Thanks @FrankVI. My Settings doesn't have Access Control in it. Please see: &lt;A href="https://imgur.com/a/LW6YhvV"&gt;https://imgur.com/a/LW6YhvV&lt;/A&gt;. Settings has: &lt;/P&gt;

&lt;P&gt;Searches, reports, and alerts&lt;BR /&gt;
Data models&lt;BR /&gt;
Event types&lt;BR /&gt;
Tags&lt;BR /&gt;
Fields&lt;BR /&gt;
Lookups&lt;BR /&gt;
User interface&lt;BR /&gt;
Advanced search&lt;BR /&gt;
All configurations&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 12:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57381#M14008</guid>
      <dc:creator>kimberlytrayson</dc:creator>
      <dc:date>2018-06-19T12:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: What indexes are included in search by default?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57382#M14009</link>
      <description>&lt;P&gt;By default, only the admins of your Splunk instance can see the link to Access controls page, because it deals with things like user account settings, user roles and authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 12:40:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-indexes-are-included-in-search-by-default/m-p/57382#M14009</guid>
      <dc:creator>janispelss</dc:creator>
      <dc:date>2018-06-19T12:40:51Z</dc:date>
    </item>
  </channel>
</rss>

