Dashboards & Visualizations

How do I change the default index name in the Splunk App for AWS Security Dashboards?

Glasses2
Communicator

Hi - 
I am trying to get the Splunk App for AWS Security Dashboards working.

Apparently the default index the app is using is "main".   I need to change this.

I know I could change the index name by editing the xml but that would require a lot of changes.

I am hoping someone knows where the central change location is located.

 

Thank you.

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Glasses2,

if you see in the macros pages [Settings -- Advanced search -- Macro], there are some macros addressing the indexes to use in the app.

Ciao.

Giuseppe

View solution in original post

Glasses2
Communicator

yes thx I accepted that over a year ago

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Glasses2,

if you see in the macros pages [Settings -- Advanced search -- Macro], there are some macros addressing the indexes to use in the app.

Ciao.

Giuseppe

chaker
Contributor

Try updating the macro's to reflect the correct index

https://docs.splunk.com/Documentation/AWS/6.0.3/Installation/Macros

yr
Loves-to-Learn Everything

Hi 

We have installed splunk Add-on for AWS and configure the inputs and we see the cloudtrail and cloudwatch data thru s3 bucket inputs. then we installed Splunk apps for aws security dashboards but some how we dont see any of our data. just fyi we have custom index ( it is not default 'main' index) so where do we change the index so that we can see data in dashboard??

 

0 Karma

chaker
Contributor

@gcusellohas provided the solution above.

https://docs.splunk.com/Documentation/AWS/6.0.3/Installation/Macros

You will need to update the macro definition to describe the index where the data resides.

0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...