- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi -
I am trying to get the Splunk App for AWS Security Dashboards working.
Apparently the default index the app is using is "main". I need to change this.
I know I could change the index name by editing the xml but that would require a lot of changes.
I am hoping someone knows where the central change location is located.
Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Glasses2,
if you see in the macros pages [Settings -- Advanced search -- Macro], there are some macros addressing the indexes to use in the app.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes thx I accepted that over a year ago
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Glasses2,
if you see in the macros pages [Settings -- Advanced search -- Macro], there are some macros addressing the indexes to use in the app.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Try updating the macro's to reflect the correct index
https://docs.splunk.com/Documentation/AWS/6.0.3/Installation/Macros
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
We have installed splunk Add-on for AWS and configure the inputs and we see the cloudtrail and cloudwatch data thru s3 bucket inputs. then we installed Splunk apps for aws security dashboards but some how we dont see any of our data. just fyi we have custom index ( it is not default 'main' index) so where do we change the index so that we can see data in dashboard??
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

@gcusellohas provided the solution above.
https://docs.splunk.com/Documentation/AWS/6.0.3/Installation/Macros
You will need to update the macro definition to describe the index where the data resides.
