Splunk Search

Splunk search goes through 'main' index only

africates
Explorer

Hi,

When I try to search anything through either 'Search & Reporting' or 'Splunk App for Windows Infrastructure' I am getting results only from 'main' index.

The same applies to 'Data Summary' - I'm only able to see the hosts which forwarded some events to 'main' index.

Can I change this somehow so search is executed on all indexes apart from these internal ones?

thanks
p

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You could either specify the index(es) you want to search in the search itself:

index=A OR index=B sourcetype=foo ...

Or you can add more indexes to the indexes searched by default for your user's role... which by default only searches index=main. There even is a button for "all non-internal indexes" at Settings -> Authentication -> Roles -> Your Role -> all the way at the bottom

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You could either specify the index(es) you want to search in the search itself:

index=A OR index=B sourcetype=foo ...

Or you can add more indexes to the indexes searched by default for your user's role... which by default only searches index=main. There even is a button for "all non-internal indexes" at Settings -> Authentication -> Roles -> Your Role -> all the way at the bottom

Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...