All Apps and Add-ons

Splunk Add-on for NetApp Data ONTAP: Why doesn't a search that only uses source & source types not work unless i add an index?

Skins
Path Finder

Using a Splunk built app (netapp) where all the searches start with source OR source type.

Now these searches should just work so they are index agnostic correct ? - well they don't, unless I add the index to the searches beforehand.

index=ontap

But that means i have to edit each panel\macro etc to make the searches work.

Am i missing a step ?

gratzi

1 Solution

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

View solution in original post

Skins
Path Finder

thanks - i added the role to my account on the HF for data collection but not to the account on the SH

0 Karma

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...