All Apps and Add-ons

Indexes searched by CIM data models

richkappler
Path Finder

Need clarification. In Manage Apps>Splunk_SA_CIM>CIM Setup, I have a list of all the data models and table with all the indexes I have available, with a checkbox next to each.

At the top it says: By default a datamodel will search across all indexes. Use the configuration panel below to constrain data model searches to specific indexes.

Does checking the checkbox next to an index exclude or include it?

0 Karma
1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

It includes that index and excludes all others.

It's either "search all by default if none are selected" or "search only these ones that I have selected."

View solution in original post

rpille_splunk
Splunk Employee
Splunk Employee

It includes that index and excludes all others.

It's either "search all by default if none are selected" or "search only these ones that I have selected."

richkappler
Path Finder

how can I "EXCLUDE" a single specific index? Only by checking the box for all the others?

0 Karma

micahkemp
Champion

Look at macros.conf in the CIM app. There is a macro for each datamodel, which defaults to some incantation of everything. You can set this to a search that excludes indexes, or includes, or whatever else you want to put in there that is a valid search.

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...