Security

In the searchhead GUI only 1000 available search indexes are shown

devopsaab
Observer

In Access Management - Role - available search indexes , only 1000 indexes are shown while we have more than 1000 indexes. Is there a way to increase this limit ? 

We run splunk 7.3.3

Labels (1)
0 Karma

devopsaab
Observer

I solved this issue by 

Placing a splunk 6.x version of authentication_roles.xmlin /opt/splunk/etc/apps/search/local/data/ui/manager/

In this file, the count of  "srchIndexesDefault"  and "srchIndexesAllowed"  can be increased

After changing this file , the file on the searchhead must be reloaded (debug/refresh or splunk restart)

0 Karma

Richfez
SplunkTrust
SplunkTrust

TLDR; this is probably "hard coded" into the app.  But I put "hard coded" into quotes because it's just javascript and is editable as per the below:

https://community.splunk.com/t5/Archive/7-3-Index-Selection-for-roles-does-not-show-all-indexes/m-p/...

If that answers your question, please give them a dose of karma as well as this answer!

-Rich

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...