- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Using a Splunk built app (netapp) where all the searches start with source OR source type.
Now these searches should just work so they are index agnostic correct ? - well they don't, unless I add the index to the searches beforehand.
index=ontap
But that means i have to edit each panel\macro etc to make the searches work.
Am i missing a step ?
gratzi
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.
To add role to your user go to Settings > Access controls > Users.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks - i added the role to my account on the HF for data collection but not to the account on the SH
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.
To add role to your user go to Settings > Access controls > Users.
