All Apps and Add-ons

What is the thought process behind having 4 separate indexes for the Splunk App for Jenkins?

davebo1896
Communicator

Can I combine the jenkins data into one index? Why do I have to maintain four new indexes for one app?

0 Karma

Richfez
SplunkTrust
SplunkTrust

There are various reasons for multiple indexes. The top few paragraphs in the docs on creating custom indexes are an easy but useful read on they why. I don't know in this particular case why there would be four indexes, but in other apps I've found the primary reasons are for control of retention or permissions. For instance, the configuration changes your firewall is reporting in may need both a different retention and also a different set of people reviewing them than the actual traffic your firewall is reporting needs.

davebo1896
Communicator

Nevermind, I see the index names are hardcoded all over the app.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...