All Apps and Add-ons

Splunk App for Web Analytics: How to specify a certain index for searches in built-in reports?

rameshlpatel
Communicator

Hi,

All reports by default are not using an index in searches. However, I am using my specific index where all data is stored. How do I point all reports to my index by default?

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

I don't have the app, but as you said the docs for it imply that it's not index specific. That's OK, there are two ways mentioned or implied by the above that may work for your needs. Read both and see which one is better suited toward your needs.

First, try going to Settings/Event types and changing the search string for the event type "web-traffic" to include an "index=myindex ..." at the front of it.

Second, and probably not as effective and more work to keep up (and potentially with more side effects as well) you may be able to set the "default indexes searched" for the user involved to include the index that has this data. Then as long as the sourcetype is set right, it ought to work.

If this resolves your issue, could you please mark this Answered so that others can better rely on it? Thanks!

View solution in original post

Richfez
SplunkTrust
SplunkTrust

I don't have the app, but as you said the docs for it imply that it's not index specific. That's OK, there are two ways mentioned or implied by the above that may work for your needs. Read both and see which one is better suited toward your needs.

First, try going to Settings/Event types and changing the search string for the event type "web-traffic" to include an "index=myindex ..." at the front of it.

Second, and probably not as effective and more work to keep up (and potentially with more side effects as well) you may be able to set the "default indexes searched" for the user involved to include the index that has this data. Then as long as the sourcetype is set right, it ought to work.

If this resolves your issue, could you please mark this Answered so that others can better rely on it? Thanks!

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...