All Apps and Add-ons

define index for my app

manikdham
Path Finder

i am creating a Splunk app. How do i define only a particular index to be used by the app. Only a particular index must be accessed from the app. where do i define the configurations.

Tags (4)

sdaniels
Splunk Employee
Splunk Employee

In inputs.conf you'll define the index you want for all of your inputs. In indexex.conf you will define where the index is stored.

[yourindex]
homePath = $SPLUNK_DB/yourindex/db
coldPath = $SPLUNK_DB/yourindex/colddb
thawedPath = $SPLUNK_DB/yourindex/thaweddb
maxTotalDataSizeMB = 10000

Then in all of your app searches and reports they will reference your index (start with index=yourindex). There is no way to assign an index to an app that i am aware of similar to how you can assign indexes to roles.

yulsplunkops
Engager

What about defining this on a Cloud Index you create ?   I get a defaut app assigned and there is no filed available to edit this.

Thanks

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You can put in comments underneath the answers rather than creating a new answer. You create the app, which is only going to have views and dashboards on your index. Then you will create a user role that only has access to that index and give those users access to your app as well.

0 Karma

manikdham
Path Finder

i want to configure app such that i listens to data from particular index. Objective is to provide users accessing app access data from particular index. what is the other way i can do this.

0 Karma

manikdham
Path Finder

in which file do i make the changes....

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

You can set this up by creating an index.conf in $SPLUNK_HOME/etc/apps//default and adding an index configuration there.

Brian

Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...