All Apps and Add-ons

Uptime Monitoring issue ver 1.2.3

jparct
Explorer

When I create a new input and change the index from default to another index, nothing is logged. If I don't change the index, logging is fine. Is this an issue or should I just use the default index?

Tags (1)
0 Karma
1 Solution

LukeMurphey
Champion

You need to add the index to the list of indexes that are searched by default for this to work. to do this:

  1. Open the role that needs to access the index from Splunk' configuration page (Access controls » Roles)
  2. Look for the option for "Indexes searched by default". Ensure that the index with the data is added to "Selected indexes".

View solution in original post

0 Karma

LukeMurphey
Champion

You need to add the index to the list of indexes that are searched by default for this to work. to do this:

  1. Open the role that needs to access the index from Splunk' configuration page (Access controls » Roles)
  2. Look for the option for "Indexes searched by default". Ensure that the index with the data is added to "Selected indexes".

View solution in original post

0 Karma

jparct
Explorer

Brilliant! Thanks a bunch!!

0 Karma

jparct
Explorer

When I search the custom index I can see data, but nothing appears on the Sparkline graph.alt text

0 Karma

LukeMurphey
Champion

Can you confirm that the data is available in the index by searching it directly (like using the search page to look for "| search index=customindex")?

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.