All Apps and Add-ons

Index created in the default (launcher) app

louieb3
Path Finder

I made the mistake of creating an index while in the launcher app. The effect is that when I go into Settings, Index, the App column shows "launcher" instead of the app that the index should be in. The index already has some data in it so I am hesitant to delete and start over. Is it possible to change the "app" of an index? Or should I not even worry about it?

Tags (2)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Step one, don't worry about it.
Step two, if you happen to have your indexer down for some reason, move the index definition from etc/apps/launcher/local/indexes.conf to etc/apps/whereeveryoulike/local/indexes.conf.

View solution in original post

louieb3
Path Finder

So it seems the easy answer is to just create all indexes in the launcher app. Except if you are planning to package the app for distribution. Then,

"If you package up an app and move it… and you intend to take the index definition with it… ie, you want that index created, blank and ready for the new location… you need the indexes.conf in the app.
But when it's all running… it doesn't matter where it's defined, just that your role gives you permission to see it."

(Above quote from Rosie)

0 Karma

louieb3
Path Finder

Something else I learned from a source that was not answers.splunk.com (thank you Rosie). While Martin's answer below is correct, there is an instance when you should worry - and that is if you create an index in an app other than launcher or search. You are perfectly OK if the app will never get deleted. But if you are in an app and create an index for a second app, and then you delete the first app, the index goes away with it.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Step one, don't worry about it.
Step two, if you happen to have your indexer down for some reason, move the index definition from etc/apps/launcher/local/indexes.conf to etc/apps/whereeveryoulike/local/indexes.conf.

louieb3
Path Finder

Thank you.

0 Karma

nmclaughl1
Explorer

Martin, thanks for step one! Does this logic apply to TCP/UDP inputs created in the GUI on an HF and then found in /etc/apps/launcher/local/inputs.conf?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...