All Apps and Add-ons

non-default Index

sov_gwright
New Member

How do I get the App for Web Analytics to look at data in a different index? I made sure to add all non-default indexes to my role and when I search for "index=blah and tag=web" I see all of the correct data with file, site etc fields populated but if I remove "index=blah" no data shows up so Web Analytics isn't seeing the other index.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @sov_gwright,
you can have two different approach:

  • modify index search default path for the roles used in your App in [Settings -- Roles -- <your_role> -- Indexes -- Default];
  • modify eventtype web-traffic in your app: copying eventtypes.conf from default to local folder (if not present, create it) and modifying the first eventtype web-traffic adding the indexes to use.

I always prefer the second solution.

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sov_gwright,
you can have two different approach:

  • modify index search default path for the roles used in your App in [Settings -- Roles -- <your_role> -- Indexes -- Default];
  • modify eventtype web-traffic in your app: copying eventtypes.conf from default to local folder (if not present, create it) and modifying the first eventtype web-traffic adding the indexes to use.

I always prefer the second solution.

Ciao.
Giuseppe

0 Karma

sov_gwright
New Member

Thanks that worked perfectly - now I'm struggling with Pages and Page Views as it only seems to want to see GET when 99% of our traffic is not GET.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sov_gwright,
good, I'm glad to help you.
about the new question, me or other people in Community will surely help you, but, please create a new request.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...