Skip to content

Splunk Add-on : App sends data to both main and configured index  #765

@Mohammed-Khan-DSO

Description

@Mohammed-Khan-DSO

Hi,
I have installed the add-on to our Splunk Cloud instance however the app does not allow for any index configuration so it uses by default main. The splunk Cloud ACS API does not allow for input configuration changes such as this to be performed via the API.

Is there some step or interaction that I am unaware of that will allow me to change the index the app uses to anything of my choosing rather than defaulting to main.

Edit: I was able to change the index in the data inputs > HCP Terraform for Splunk > Index setting. However having changed that setting it is still sending data into the main index. Both indexes are receiving the same data, doubling out license consumption for the same data source

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions