Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Splunk Add-on : App sends data to both main and configured index #765

Open
Mohammed-Khan-DSO opened this issue Oct 25, 2024 · 0 comments
Open

Comments

@Mohammed-Khan-DSO
Copy link

Mohammed-Khan-DSO commented Oct 25, 2024

Hi,
I have installed the add-on to our Splunk Cloud instance however the app does not allow for any index configuration so it uses by default main. The splunk Cloud ACS API does not allow for input configuration changes such as this to be performed via the API.

Is there some step or interaction that I am unaware of that will allow me to change the index the app uses to anything of my choosing rather than defaulting to main.

Edit: I was able to change the index in the data inputs > HCP Terraform for Splunk > Index setting. However having changed that setting it is still sending data into the main index. Both indexes are receiving the same data, doubling out license consumption for the same data source

@Mohammed-Khan-DSO Mohammed-Khan-DSO changed the title Splunk Add-on : No Index Configuration Splunk Add-on : App sends data to both main and configured index Oct 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant