All Apps and Add-ons

What is the "index" field for in the metadata section after you complete a DB Connect query?

splunknoob408
Explorer

More specifically, what do the available options mean?

alt text

I can't find anything online that explains what you're supposed to put there. The available options don't seem to have any relevance to my database schema, which I would expect if it's indexing...

Tags (2)
0 Karma
1 Solution

niketn
Legend

@splunknoob408, seems like you are setting up DB Connect on fresh installation of Splunk Enterprise as these are default indexes that are created in Splunk. You would want to create a new index for your DB Connect Data (or your Splunk App data, depending on the need).

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes
OR
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes

Unless you have already done so, you should check out the demo videos of setting up DB Connect : https://splunkbase.splunk.com/app/2686/ OR https://www.youtube.com/watch?v=Q1Q3XvChI50

OR the DB Connect Documentation for complete details: http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Createandmanagedatabaseinputs

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@splunknoob408, seems like you are setting up DB Connect on fresh installation of Splunk Enterprise as these are default indexes that are created in Splunk. You would want to create a new index for your DB Connect Data (or your Splunk App data, depending on the need).

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes
OR
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes

Unless you have already done so, you should check out the demo videos of setting up DB Connect : https://splunkbase.splunk.com/app/2686/ OR https://www.youtube.com/watch?v=Q1Q3XvChI50

OR the DB Connect Documentation for complete details: http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Createandmanagedatabaseinputs

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

splunknoob408
Explorer

Thank you, I will read the docs and watch the video. I did a tutorial for DB Connect, but I don't recall it explaining how to create the index -- I think it was already in the list because he was using standard Splunk log data.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...