All Apps and Add-ons

Splunk App for Nextcloud: How to change index the App uses

wemb
Explorer

We're pushing out a trial deployment of NC and are using a clustered index arrangement. I don't want my NC data to be imported into the default indexer, so I've adjusted the inputs.conf to pull the data into an index called 'nextcloud'. However, I've just realized the app doesn't seem to by specify an index to pull it's data from and so it shows me nothing it's collecting from the event logs (because the event logs it's expecting aren't in whatever index you search when you don't have an 'index=...' in your searches?

Is there a way to override or set the default index for the Nextcloud app to do its searches against my 'nextcloud' index?

Thanks - very much a Splunk newbie here.

0 Karma
1 Solution

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

View solution in original post

0 Karma

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

0 Karma

bgraabek_splunk
Splunk Employee
Splunk Employee

The above may be clear enough. I would add that several indexes can be "default" indexes, so as an example both the "main" and the "nextcloud" indexes can be default indexes.
Any index that is a "default" index can be searched without specifying the "index=.

0 Karma

wemb
Explorer

Thanks for that! I hadn't realised this was a thing you could do - very glad I can provide access to the different indexes on a per role basis.
Cheers!
Dave

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...