All Apps and Add-ons

Splunk App for Nextcloud: How to change index the App uses

wemb
Explorer

We're pushing out a trial deployment of NC and are using a clustered index arrangement. I don't want my NC data to be imported into the default indexer, so I've adjusted the inputs.conf to pull the data into an index called 'nextcloud'. However, I've just realized the app doesn't seem to by specify an index to pull it's data from and so it shows me nothing it's collecting from the event logs (because the event logs it's expecting aren't in whatever index you search when you don't have an 'index=...' in your searches?

Is there a way to override or set the default index for the Nextcloud app to do its searches against my 'nextcloud' index?

Thanks - very much a Splunk newbie here.

0 Karma
1 Solution

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

View solution in original post

0 Karma

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

0 Karma

bgraabek_splunk
Splunk Employee
Splunk Employee

The above may be clear enough. I would add that several indexes can be "default" indexes, so as an example both the "main" and the "nextcloud" indexes can be default indexes.
Any index that is a "default" index can be searched without specifying the "index=.

0 Karma

wemb
Explorer

Thanks for that! I hadn't realised this was a thing you could do - very glad I can provide access to the different indexes on a per role basis.
Cheers!
Dave

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...