All Apps and Add-ons

Windows App and multiple indexes

bulliarda
Explorer

Hello, I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine. However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??). Does someone know how to do it?

Thanks.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

bulliarda
Explorer

Excellent it works.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...