All Apps and Add-ons

Why am I unable to select the custom index created in the indexer?

AL3Z
Builder

Hi,

We are using the intsights app for splunk cloud as the intsights app installed on splunk idm,we notice that when we try to create a inputs to get the alerts,we are not able to select the custom index created in the indexer.

Why the all indexes which are present in splunk cloud not populating in the intsights app splunk idm ??

 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AL3Z,

indexes created on on-premise Indexers aren't visible on on premise Search Heads, but on Splunk Cloud you should be able to see all Indexes.

Check the grants of the user you're using.

Ciao.

Giuseppe

0 Karma

AL3Z
Builder

@gcusello 

We have created the index in splunk cloud only it's not populating in the intsights app

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AL3Z,

I suppose that this app is installed in Splunk Cloud, or not?

if on-premise, it's a different thing: it's normal that you don't see it, it's the same thing if you have an Indexer an a Search Head.

In this case you have two solutions: configure the index in the input.conf file, create an empry index with the same name on the on-premise Search Head.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...