All Apps and Add-ons

Splunk App for Web Analytics: How to specify a certain index for searches in built-in reports?

rameshlpatel
Communicator

Hi,

All reports by default are not using an index in searches. However, I am using my specific index where all data is stored. How do I point all reports to my index by default?

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

I don't have the app, but as you said the docs for it imply that it's not index specific. That's OK, there are two ways mentioned or implied by the above that may work for your needs. Read both and see which one is better suited toward your needs.

First, try going to Settings/Event types and changing the search string for the event type "web-traffic" to include an "index=myindex ..." at the front of it.

Second, and probably not as effective and more work to keep up (and potentially with more side effects as well) you may be able to set the "default indexes searched" for the user involved to include the index that has this data. Then as long as the sourcetype is set right, it ought to work.

If this resolves your issue, could you please mark this Answered so that others can better rely on it? Thanks!

View solution in original post

Richfez
SplunkTrust
SplunkTrust

I don't have the app, but as you said the docs for it imply that it's not index specific. That's OK, there are two ways mentioned or implied by the above that may work for your needs. Read both and see which one is better suited toward your needs.

First, try going to Settings/Event types and changing the search string for the event type "web-traffic" to include an "index=myindex ..." at the front of it.

Second, and probably not as effective and more work to keep up (and potentially with more side effects as well) you may be able to set the "default indexes searched" for the user involved to include the index that has this data. Then as long as the sourcetype is set right, it ought to work.

If this resolves your issue, could you please mark this Answered so that others can better rely on it? Thanks!

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...