When installing the Rapid7 App, I added to `$SPLUNK_HOME\etc\apps\rapid7\local\inputs.conf` under the [monitor] stanza `index=nexpose_index`. The data from the lookup tables is properly indexed into the correct index, although the dashboard and the saved searches are looking at the default index. Therefore, the dashboard shows "no results".
I'd rather not use the default index for this data. Any help would be appreciated.
↧