All Apps and Add-ons

Windows App and multiple indexes

bulliarda
Explorer

Hello, I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine. However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??). Does someone know how to do it?

Thanks.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

bulliarda
Explorer

Excellent it works.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!