Hi -
I am trying to get the Splunk App for AWS Security Dashboards working.
Apparently the default index the app is using is "main". I need to change this.
I know I could change the index name by editing the xml but that would require a lot of changes.
I am hoping someone knows where the central change location is located.
Thank you.
Hi @Glasses2,
if you see in the macros pages [Settings -- Advanced search -- Macro], there are some macros addressing the indexes to use in the app.
Ciao.
Giuseppe
Hi @Glasses2,
if you see in the macros pages [Settings -- Advanced search -- Macro], there are some macros addressing the indexes to use in the app.
Ciao.
Giuseppe
Try updating the macro's to reflect the correct index
https://docs.splunk.com/Documentation/AWS/6.0.3/Installation/Macros