In previous Splunk releases, you used the command line interface (CLI) to manage your indexes. Now, you can view your indexes, edit their properties, and add new indexes from the Admin page of Splunk Web.
Note: To apply any changes that you make to the indexes, such as editing properties or adding a new index, you must restart Splunk. In Splunk Web, you can restart the Splunk server from Admin > Server: Control Server. Just click Restart Now.
View and manage indexesThe Admin > Index: View/Manage Indexes page displays a table of all your indexes and their properties, including:
Clicking on an index name opens a page that lets you view and edit that index's properties. Properties that you cannot change are grayed out and include:
Properties that you can redefine include:
After you make your changes, click Update. Then, restart Splunk to apply your changes.
Create new indexThe Admin > Indexes: Create Index page lets you define the properties for a new index. To create a new index, enter:
If you check Advanced settings, the list of properties expands. Advanced properties include:
After editing the index's properties, click Add. Then, restart Splunk to save and apply your changes.
Comments
No comments have been submitted.