All Apps and Add-ons

How do I modify configurations for an splunk app installed on splunk cloud?

fl66
Observer

Hi,

I installed a splunk app and events are sent to default index. But I need to change the index to be a custom index. I tried to create  local/inputs.conf file and repackaged the app. The app was rejected when I uploaded it to splunk cloud even if I changed the appID. 

 

I also looked at Splunk ACS API, but could not figure out if that can be used to customize configuration files and what are the endpoint URL to use.

thanks in advance.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fl66 ,

you could add a new custom index by interface and them modify your input to send logs to that index, where are these inputs, still on Splunk Cloud or on premise?

If on Splunk Cloud. modify them by interface or uploading a new version of the app, if on premise, modify them in the on premise installed version.

Ciao.

Giuseppe.

0 Karma

fl66
Observer

The app was installed from splunkbase. I tried to add the inputs.conf file to change to a custom index. The new package was rejected when I uploaded to splunk cloud, even if I changed the app ID.

 

Thank you!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fl66 ,

if you installed from Splunkbase, the only way it to modify configurations by GUI, in other words:

  • go in [Settings > Indexes] and add a new custom input,
  • go in [Settings > inputs, search for the inputs of your app and manually (by gui) modify the index.

Ciao.

Giuseppe

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...