All Apps and Add-ons

Splunk App for Nextcloud: How to change index the App uses

wemb
Explorer

We're pushing out a trial deployment of NC and are using a clustered index arrangement. I don't want my NC data to be imported into the default indexer, so I've adjusted the inputs.conf to pull the data into an index called 'nextcloud'. However, I've just realized the app doesn't seem to by specify an index to pull it's data from and so it shows me nothing it's collecting from the event logs (because the event logs it's expecting aren't in whatever index you search when you don't have an 'index=...' in your searches?

Is there a way to override or set the default index for the Nextcloud app to do its searches against my 'nextcloud' index?

Thanks - very much a Splunk newbie here.

0 Karma
1 Solution

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

View solution in original post

0 Karma

chris1337
Explorer

Hi, try to do the following:

Go to Settings -> Access controls -> Roles -> "Your Role" -> Indexes
and set the nextcloud index as default

Then open the app again.

Greetings

0 Karma

bgraabek_splunk
Splunk Employee
Splunk Employee

The above may be clear enough. I would add that several indexes can be "default" indexes, so as an example both the "main" and the "nextcloud" indexes can be default indexes.
Any index that is a "default" index can be searched without specifying the "index=.

0 Karma

wemb
Explorer

Thanks for that! I hadn't realised this was a thing you could do - very glad I can provide access to the different indexes on a per role basis.
Cheers!
Dave

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...