All Apps and Add-ons

Splunk App for Nextcloud: How to change index the App uses

wemb
Explorer

We're pushing out a trial deployment of NC and are using a clustered index arrangement. I don't want my NC data to be imported into the default indexer, so I've adjusted the inputs.conf to pull the data into an index called 'nextcloud'. However, I've just realized the app doesn't seem to by specify an index to pull it's data from and so it shows me nothing it's collecting from the event logs (because the event logs it's expecting aren't in whatever index you search when you don't have an 'index=...' in your searches?

Is there a way to override or set the default index for the Nextcloud app to do its searches against my 'nextcloud' index?

Thanks - very much a Splunk newbie here.

0 Karma
1 Solution

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

View solution in original post

0 Karma

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

0 Karma

bgraabek_splunk
Splunk Employee
Splunk Employee

The above may be clear enough. I would add that several indexes can be "default" indexes, so as an example both the "main" and the "nextcloud" indexes can be default indexes.
Any index that is a "default" index can be searched without specifying the "index=.

0 Karma

wemb
Explorer

Thanks for that! I hadn't realised this was a thing you could do - very glad I can provide access to the different indexes on a per role basis.
Cheers!
Dave

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...