All Apps and Add-ons

How do I modify configurations for an splunk app installed on splunk cloud?

fl66
Observer

Hi,

I installed a splunk app and events are sent to default index. But I need to change the index to be a custom index. I tried to create  local/inputs.conf file and repackaged the app. The app was rejected when I uploaded it to splunk cloud even if I changed the appID. 

 

I also looked at Splunk ACS API, but could not figure out if that can be used to customize configuration files and what are the endpoint URL to use.

thanks in advance.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fl66 ,

you could add a new custom index by interface and them modify your input to send logs to that index, where are these inputs, still on Splunk Cloud or on premise?

If on Splunk Cloud. modify them by interface or uploading a new version of the app, if on premise, modify them in the on premise installed version.

Ciao.

Giuseppe.

0 Karma

fl66
Observer

The app was installed from splunkbase. I tried to add the inputs.conf file to change to a custom index. The new package was rejected when I uploaded to splunk cloud, even if I changed the app ID.

 

Thank you!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fl66 ,

if you installed from Splunkbase, the only way it to modify configurations by GUI, in other words:

  • go in [Settings > Indexes] and add a new custom input,
  • go in [Settings > inputs, search for the inputs of your app and manually (by gui) modify the index.

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...