All Apps and Add-ons

Splunk App for Nextcloud: How to change index the App uses

wemb
Explorer

We're pushing out a trial deployment of NC and are using a clustered index arrangement. I don't want my NC data to be imported into the default indexer, so I've adjusted the inputs.conf to pull the data into an index called 'nextcloud'. However, I've just realized the app doesn't seem to by specify an index to pull it's data from and so it shows me nothing it's collecting from the event logs (because the event logs it's expecting aren't in whatever index you search when you don't have an 'index=...' in your searches?

Is there a way to override or set the default index for the Nextcloud app to do its searches against my 'nextcloud' index?

Thanks - very much a Splunk newbie here.

0 Karma
1 Solution

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

View solution in original post

0 Karma

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

0 Karma

bgraabek_splunk
Splunk Employee
Splunk Employee

The above may be clear enough. I would add that several indexes can be "default" indexes, so as an example both the "main" and the "nextcloud" indexes can be default indexes.
Any index that is a "default" index can be searched without specifying the "index=.

0 Karma

wemb
Explorer

Thanks for that! I hadn't realised this was a thing you could do - very glad I can provide access to the different indexes on a per role basis.
Cheers!
Dave

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...