All Apps and Add-ons

Splunk Add-on for NetApp Data ONTAP: Why doesn't a search that only uses source & source types not work unless i add an index?

Skins
Path Finder

Using a Splunk built app (netapp) where all the searches start with source OR source type.

Now these searches should just work so they are index agnostic correct ? - well they don't, unless I add the index to the searches beforehand.

index=ontap

But that means i have to edit each panel\macro etc to make the searches work.

Am i missing a step ?

gratzi

1 Solution

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

View solution in original post

Skins
Path Finder

thanks - i added the role to my account on the HF for data collection but not to the account on the SH

0 Karma

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...