All Apps and Add-ons

Windows App and multiple indexes

bulliarda
Explorer

Hello, I have multiple indexes because I want multiple retention policies. I want WinEventLog:Security to go to index A and keep it for 12 months and WinEventLog:System to go to index B and keep it for 2 months. I change it in the inputs.conf of my deployed clients and it works fine. However, now the Windows App doesn't work anymore. It seems that the app is only looking in a particular index (main ??). Does someone know how to do it?

Thanks.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

The Windows app doesn't specify any index at all, so the default indexes of the user/role will be used. You could just add the new indexes to the default indexes for your role to make it work again.

bulliarda
Explorer

Excellent it works.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...