Deployment Architecture

customized *NIX app for external users

konradwawryn
Explorer

Hi,

since few days Im trying to configure access to *NIX application to my external users.
I
m using that application to monitor my linux servers located in the cloud. To keep separate data for each group of the servers I created dedicated indexes and users.
Each user have access only to his own index.

Problem:
Im login with user "teama", Im clicking on *UNIX app. Next from the top menu I`m choosing:

CPU -- > CPU by host

alt text

And it seems that is not working. In index for that user I see CPU data. It seems that *UNIX app searching by default in "os" index. How to change it ? I need to setup for each user different default index. Maybe somebody could support me ?

alt text

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

Unfortunately version 4.6 and before of the *nix app is hard coded to index=os. This is was a mistake. To fix, you would have to copy unix/default/savedsearches.conf to unix/local/savedsearches.conf and change the references to index=os to the index where your data lives.

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

Unfortunately version 4.6 and before of the *nix app is hard coded to index=os. This is was a mistake. To fix, you would have to copy unix/default/savedsearches.conf to unix/local/savedsearches.conf and change the references to index=os to the index where your data lives.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...