All Apps and Add-ons

Windows App and multiple indexes

Explorer

Hello, I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine. However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??). Does someone know how to do it?

Thanks.

1 Solution

Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

Explorer

Excellent it works.

0 Karma