<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index not on searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74979#M18952</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;The app seems to use eventtypes and not specify the index on searches. I can see that all events get forced to the index "ios" but without specifying the index for searching no events are picked up.&lt;/P&gt;

&lt;P&gt;I understand splunk only searches "main" if you don't put the index in, so why would the searches in this app not specify index="ios" please ? &lt;/P&gt;

&lt;P&gt;I know I must be missing something, but at this point it looks like I have to change every search to include index="ios".&lt;/P&gt;

&lt;P&gt;Many Thanks&lt;BR /&gt;
Derek&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2013 16:20:55 GMT</pubDate>
    <dc:creator>DerekKing</dc:creator>
    <dc:date>2013-06-25T16:20:55Z</dc:date>
    <item>
      <title>Index not on searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74979#M18952</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;The app seems to use eventtypes and not specify the index on searches. I can see that all events get forced to the index "ios" but without specifying the index for searching no events are picked up.&lt;/P&gt;

&lt;P&gt;I understand splunk only searches "main" if you don't put the index in, so why would the searches in this app not specify index="ios" please ? &lt;/P&gt;

&lt;P&gt;I know I must be missing something, but at this point it looks like I have to change every search to include index="ios".&lt;/P&gt;

&lt;P&gt;Many Thanks&lt;BR /&gt;
Derek&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 16:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74979#M18952</guid>
      <dc:creator>DerekKing</dc:creator>
      <dc:date>2013-06-25T16:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Index not on searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74980#M18953</link>
      <description>&lt;P&gt;1) To which app are you referring?&lt;/P&gt;

&lt;P&gt;2) You can adjust the list of indexes searched by default (that is, unless you provide an index= keyword in your search) by visiting the Splunk Manager &amp;gt; Access Controls &amp;gt; Roles &amp;gt; &amp;lt;select role&amp;gt;, then update the list of default indexes. Out of the box, it's only "main".&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 16:31:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74980#M18953</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-06-25T16:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Index not on searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74981#M18954</link>
      <description>&lt;P&gt;Ahh posted incorrectly. I was referring to CiscoIos, but you have resolved my issue thankyou.&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Derek&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 16:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-not-on-searches/m-p/74981#M18954</guid>
      <dc:creator>DerekKing</dc:creator>
      <dc:date>2013-06-25T16:39:39Z</dc:date>
    </item>
  </channel>
</rss>

