Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Rapid7 App for Splunk Enterprise: How to change the "default" index so that the dashboard looks at another index?

$
0
0
When installing the Rapid7 App, I added to `$SPLUNK_HOME\etc\apps\rapid7\local\inputs.conf` under the [monitor] stanza `index=nexpose_index`. The data from the lookup tables is properly indexed into the correct index, although the dashboard and the saved searches are looking at the default index. Therefore, the dashboard shows "no results". I'd rather not use the default index for this data. Any help would be appreciated.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>