How can I change aws app scheduled searches to use aws data in index aws_data instead of default (main)?
I have Splunk Cloud environment
I am configuring the aws add-on for splunk inputs to place data in an index called aws_data rather than have it go to default (main) index...
I see data in my aws_data index but splunk app doesn't seem to see it with its scheduled searches... Do i need to sitch the data index back to default (main) for the app to properly process the data in its dashboards or can I change which index the schedule searches use using the CIM tool or other methods??
Thank you
Rich
You can edit the macros.conf and change all instances of "index=main" to "index=aws_data"
You can edit the macros.conf and change all instances of "index=main" to "index=aws_data"