Use a custom index for storing AWS accounts and inputs data
Most configuration for the app is handled in the add-on. For information on how to set up and manage the configuration for your AWS accounts and inputs using the Splunk Add-on for AWS, see Installation overview for the Splunk Add-on for AWS in the Splunk Add-on for AWS manual.
By default, your AWS accounts and inputs data are stored in a predefined index named "summary." If you want to use a custom index, perform the following steps:
- Create an index in which you want to store AWS accounts and inputs data. You must create the index on an indexer or indexer cluster, and not on a search head or heavy forwarder. See Create custom indexes for information about creating an index.
- In the Splunk Add-on for AWS, modify the
aws-account-index
andaws-input-index
macros to include the custom index you created. - Go to Settings > Advanced Search > Search Macros.
- Select the the macro from the list.
- For the
index
field, replacesummary
with the name of the index you created. - In the Splunk Add-on for AWS, run these saved searches: Addon Metadata - Migrate AWS Accounts and Addon Metadata - Summarize AWS Inputs.
- Go to Settings > searches, reports, and alerts.
- In the Actions column, click Run for each saved search.
- In the Splunk App for AWS, modify the
aws-account-summary
,aws-input-summary
, andaws-sourcetype-index-summary
macros to include the custom index you created. - Go to Settings > Advanced Search > Search Macros.
- Select the macro from the list.
- For the
index
field, replacesummary
with the name of the index you created. - In the Splunk App for AWS, run the Addon Synchronization saved search to sync the macros.
Configure dashboard warning messages and billing options | Upgrade the Splunk App for AWS |
This documentation applies to the following versions of Splunk® App for AWS (Legacy): 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.2.0, 6.0.1, 6.0.2, 6.0.3
Feedback submitted, thanks!