When installing the Rapid7 App, I added to
$SPLUNK_HOME\etc\apps\rapid7\local\inputs.conf under the [monitor] stanza
index=nexpose_index. The data from the lookup tables is properly indexed into the correct index, although the dashboard and the saved searches are looking at the default index. Therefore, the dashboard shows "no results".
I'd rather not use the default index for this data. Any help would be appreciated.
I haven't been able to find any reference to either sourcetypes or indexes in the dashboard configs. If anyone can see them, that would be enough I believe.
If you send the data to a different index, then you will need to do one of two things:
1) Examine all the saved searches and the inline searches in all of the dashboards. Add
index=nexpose_index to all of them as appropriate.
2) If the saved searches and inline searches contain
index=main, then you need to change the searches (option #1). But if the searches do not indicate any index, then you can change the "indexes searched by default" for the roles that will be using this app. This change is made to the role(s), not the searches.
to build in @lguinn's answer above, you need to add "index=" to the beginning of the following objects:
They can all be found under the rapid7 app's Event Types, found at https://YOUR_HOST_NAME:8000/en-US/manager/search/saved/eventtypes
Thanks for responding, that is what I thought to be the answer as well. Adding "index=" to the rapid7 app's eventtypes did work.