Using a Splunk built app (netapp) where all the searches start with source OR source type.
Now these searches should just work so they are index agnostic correct ? - well they don't, unless I add the index to the searches beforehand.
index=ontap
But that means i have to edit each panel\macro etc to make the searches work.
Am i missing a step ?
gratzi
Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.
To add role to your user go to Settings > Access controls > Users.
thanks - i added the role to my account on the HF for data collection but not to the account on the SH
Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.
To add role to your user go to Settings > Access controls > Users.