All Apps and Add-ons

Windows App and multiple indexes

bulliarda
Explorer

Hello, I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine. However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??). Does someone know how to do it?

Thanks.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

bulliarda
Explorer

Excellent it works.

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...