All Apps and Add-ons

Splunk App for Infrastructure does create the em_metrics, em_meta and infra_alerts

a_n
Path Finder

I have installed SAI on test environment (standalone Splunk instance on Centos 7) and I added a Windows 10 entity.

The entity does not appear in the UI, then  I noticed the indexes  em_metrics, em_meta and infra_alerts are not created in the Splunk.

 

Shouldn't they be created during app installation?

What should I do now?

Thank you.

 

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Those indexes are installed by the Splunk Add-on for Infrastructure, not the app.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Those indexes are installed by the Splunk Add-on for Infrastructure, not the app.

---
If this reply helps you, Karma would be appreciated.

a_n
Path Finder

Thank you very much,

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...