All Apps and Add-ons

Splunk Add-on for NetApp Data ONTAP: Why doesn't a search that only uses source & source types not work unless i add an index?

Skins
Path Finder

Using a Splunk built app (netapp) where all the searches start with source OR source type.

Now these searches should just work so they are index agnostic correct ? - well they don't, unless I add the index to the searches beforehand.

index=ontap

But that means i have to edit each panel\macro etc to make the searches work.

Am i missing a step ?

gratzi

1 Solution

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

View solution in original post

Skins
Path Finder

thanks - i added the role to my account on the HF for data collection but not to the account on the SH

0 Karma

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...