All Apps and Add-ons

Splunk App for Web Analytics: How to specify a certain index for searches in built-in reports?

rameshlpatel
Communicator

Hi,

All reports by default are not using an index in searches. However, I am using my specific index where all data is stored. How do I point all reports to my index by default?

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

I don't have the app, but as you said the docs for it imply that it's not index specific. That's OK, there are two ways mentioned or implied by the above that may work for your needs. Read both and see which one is better suited toward your needs.

First, try going to Settings/Event types and changing the search string for the event type "web-traffic" to include an "index=myindex ..." at the front of it.

Second, and probably not as effective and more work to keep up (and potentially with more side effects as well) you may be able to set the "default indexes searched" for the user involved to include the index that has this data. Then as long as the sourcetype is set right, it ought to work.

If this resolves your issue, could you please mark this Answered so that others can better rely on it? Thanks!

View solution in original post

Richfez
SplunkTrust
SplunkTrust

I don't have the app, but as you said the docs for it imply that it's not index specific. That's OK, there are two ways mentioned or implied by the above that may work for your needs. Read both and see which one is better suited toward your needs.

First, try going to Settings/Event types and changing the search string for the event type "web-traffic" to include an "index=myindex ..." at the front of it.

Second, and probably not as effective and more work to keep up (and potentially with more side effects as well) you may be able to set the "default indexes searched" for the user involved to include the index that has this data. Then as long as the sourcetype is set right, it ought to work.

If this resolves your issue, could you please mark this Answered so that others can better rely on it? Thanks!

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...