Splunk Search

How do I set the default search index in Splunk Light?

jrailton
Engager

In Splunk Enterprise you can set the default search index per user. In Splunk Light you cannot it seems?

I read another post which said you can edit the \etc\system\default\indexes.conf file and set defaultDatabase=my_new_index

And yet another post that said you should create \etc\system\local\indexes.conf file and set defaultDatabase=my_new_index

I tried both and restarted Splunk after each, but neither have made a difference.

0 Karma
1 Solution

dkoshe_splunk
Splunk Employee
Splunk Employee

create new file \etc\system\local\authorize.conf and add following stanza, to make that index searchable by default for all users:

[role_user]
srchIndexesDefault = main;my_new_index

If you want to restrict it to only Administrators, then use following stanza instead:

[role_admin]
srchIndexesDefault = main;my_new_index

and then restart Splunk Light.
Changing indexes.conf, will only change your default index when importing data.
Also, @somesoni2 is correct, you should never update conf files under default, as they will get overwritten upon updates.
Hope this helps.

View solution in original post

dkoshe_splunk
Splunk Employee
Splunk Employee

create new file \etc\system\local\authorize.conf and add following stanza, to make that index searchable by default for all users:

[role_user]
srchIndexesDefault = main;my_new_index

If you want to restrict it to only Administrators, then use following stanza instead:

[role_admin]
srchIndexesDefault = main;my_new_index

and then restart Splunk Light.
Changing indexes.conf, will only change your default index when importing data.
Also, @somesoni2 is correct, you should never update conf files under default, as they will get overwritten upon updates.
Hope this helps.

somesoni2
Revered Legend

The Splunk Light doesn't support role customization (the default searched index is role/user level attribute).

Also, you should never change any configuration from folder \etc\system\default\.

MuS
SplunkTrust
SplunkTrust

"all these worlds are yours, except /default - attempt no editing there"

-- @duckfez, 2010

http://docs.splunk.com/Documentation/Splunk/6.4.1/Admin/Configurationfiledirectories

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...