All Apps and Add-ons

Why am I unable to populate the indexes on Intsights app for Splunk in SH?

AL3Z
Builder

Hi,

While trying to configure the Instights app for splunk in my search head as I'm trying to send the alerts to test index, it is not populating in the app other than these showed indexes..

AL3Z_0-1673956471565.png

Thanks.

 

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Maybe you can try writing if you didn't already. Sometimes apps list only a few indexes but show when you write some letters.

I cannot think of any other reason.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

AL3Z
Builder

hi @scelikok 

I have the 2 search heads in our environment, If i create a index on one of the search head it get populated in the remaining  search head also , now my question is why its not populating.

ciao

Tags (1)
0 Karma

AL3Z
Builder

@scelikok 

I have tried writing the index test but it's not populating  the index name why so ??

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hİ @AL3Z,

If you are using separate indexers or indexer clustering you may not see the indexes defined on indexers or cluster. If the app does not allow you to type index name your should manually add this test index to your SH index settings. After that, you will be able to select test index. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

AL3Z
Builder

@scelikok 

I have manually added the test index to the SH where the Intsights app is installed.

Even though the created test index is not populating on the app ?

 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...