In previous Splunk releases, you used the command line interface (CLI) to manage your indexes. Now, you can view your indexes, edit their properties, and add new indexes from the Admin page of Splunk Web.
This topic discusses using Splunk Web to view and edit your indexes. To define a custom index, refer to the Create new index topic.
View and manage indexesIn Splunk Web, you can view and edit all your indexes from the Admin page:
1. On the upper righthand corner of any of the dashboards, click Admin.2. From the lefthand navigation list, click Indexes.
This takes you to the Admin > Indexess: View/Manage Indexes page which displays a table of all your indexes and their properties, including:.
From the Admin > Index: View/Manage Indexes page, click an index name to view and edit that index's properties. Properties that you cannot change are grayed out and include:
Properties that you can redefine include:
After you make your changes, click Update. Then, restart Splunk to apply your changes.
Important: To apply any changes that you make to the indexes, such as editing properties or adding a new index, you must restart Splunk. In Splunk Web, you can restart the Splunk server from Admin > Server: Control Server. Just click Restart Now.
Comments
No comments have been submitted.