Deployment Architecture

Is it possible to disable the main index?

ronak1308
New Member

When I try to disable main index in Splunk Enterprise it gives me the following error:

In handler 'indexes': cannot disable idx=main, is internal
0 Karma
1 Solution

woodcock
Esteemed Legend

Just remove main from Indexes searched by default and Available search indexes from the User role.

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

For the learning purposes, may we know why you would like disable the main index, please.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ronak1308
New Member

I want to disable main index because my one application's data is being indexed in main index and other application's data in other index, so in order to test that we are getting same fields from both the applications I need to disable the indexes of one application and test the other. And moreover I can't delete any of the applications which would be the most easiest way to test.

0 Karma

woodcock
Esteemed Legend

just specify index=other to avoid pulling in the Indexes searched by default setting (which contains Index=main).

0 Karma

woodcock
Esteemed Legend

Just remove main from Indexes searched by default and Available search indexes from the User role.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...