Splunk Search

How do I find the name of the index?

uayub
Path Finder

For performing archives, it seems I have to use the name of the index in the conf file. How do I know what index name is being used?

Thanks

Unis

Tags (2)
0 Karma

uayub
Path Finder

After reading the admin manual , it seems the default index name is main.

Thanks all.

Unis

0 Karma

uayub
Path Finder

As per the doc:

[]
coldToFrozenDir = ""

In the above what should be typed in for "index"

Also the doc mentions to create the change in the local directory. So how does this update the main indexes file in the default folder?

Thanks

0 Karma

Ayn
Legend

Huh. Could you explain in more detail what you mean?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...