All Apps and Add-ons

Splunk Add-on for NetApp Data ONTAP: Why doesn't a search that only uses source & source types not work unless i add an index?

Skins
Path Finder

Using a Splunk built app (netapp) where all the searches start with source OR source type.

Now these searches should just work so they are index agnostic correct ? - well they don't, unless I add the index to the searches beforehand.

index=ontap

But that means i have to edit each panel\macro etc to make the searches work.

Am i missing a step ?

gratzi

1 Solution

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

View solution in original post

Skins
Path Finder

thanks - i added the role to my account on the HF for data collection but not to the account on the SH

0 Karma

dauren_akilbeko
Communicator

Yes, you have to add role to your account, this will add index to default search.
http://docs.splunk.com/Documentation/NetApp/2.1.8/DeployNetapp/InstalltheSplunkAppforNetAppDataONTAP
the last step.

To add role to your user go to Settings > Access controls > Users.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...