Monitoring Splunk

Splunk 6 splunkd messages in search

ctripod
Explorer

Hi I've just deployed Splunk 6 via the Chef cookbook on-line and I'm noticing some differences from Splunk 5. There are a LOT of "sourcetype=splunkd" messages in my general searches in a custom index I created (index=staging). Also, Splunk 6 is not allowing me to just search a sourcetype I have to first put in the index. My query "sourcetype=access_custom" is returning 0 results, but "index=staging sourcetype=access_custom" works.

My questions is, how to change this behaviors and is this something new and expected in Splunk 6 or is the configuration incorrect (maybe Chef cookbook)? I've set up many Splunk 5 architectures with lots of searches and dashboards etc. and have never seen either of these two.

Thxs

Tags (3)
0 Karma

ShaneNewman
Motivator

In order to make your searches work without using a specific index you will have to change your permissions for the role you are assigned to. Just add all non internal indexes to the list of indexes searched by default.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...