User Manual

 


Manage your indexes

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Manage your indexes

In previous Splunk releases, you used the command line interface (CLI) to manage your indexes. Now, you can view your indexes, edit their properties, and add new indexes from the Admin page of Splunk Web.

This topic discusses using Splunk Web to view and edit your indexes. To define a custom index, refer to the Create new index topic.

View and manage indexes

In Splunk Web, you can view and edit all your indexes from the Admin page:

1. On the upper righthand corner of any of the dashboards, click Admin.

2. From the lefthand navigation list, click Indexes.

This takes you to the Admin > Indexess: View/Manage Indexes page which displays a table of all your indexes and their properties, including:

Edit index properties

From the Admin > Index: View/Manage Indexes page, click an index name to view and edit that index's properties. Properties that you cannot change are grayed out and include:

Properties that you can redefine include:

After you make your changes, click Update. Then, restart Splunk to apply your changes.

Important: To apply any changes that you make to the indexes, such as editing properties or adding a new index, you must restart Splunk. In Splunk Web, you can restart the Splunk server from Admin > Server: Control Server. Just click Restart Now.

This documentation applies to the following versions of Splunk: 3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 , 3.4 , 3.4.1 , 3.4.2 , 3.4.3 , 3.4.5 , 3.4.6 , 3.4.8 , 3.4.9 , 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13 , 3.4.14 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.