Splunk Search

How to search for data from other Indexes?

misteryuku
Communicator

How do i search for data from other indexes in the Splunk's search app?

Tags (1)
0 Karma

Damien_Dallimor
Ultra Champion

Specify the index name in your search :

index=someindex | ...

cvajs
Contributor

you can also edit the role to include other indexes that will be included by default, hence no need to use index=xyz

I_am_Jeff
Communicator

Damien is correct. If you don't specify an index, you'll search the one named "main". If you want to search all of your indexes, use: index="*"

If you want to search a specific index, use the name in your search: index=myindex

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...