
Configure search in
In earlier releases of search was handled by an embedded version of Splunk Enterprise. Beginning with release 6.2.0, uses PostgreSQL full-text search, which has been modified to accept the *
wildcard. For search syntax and examples, see Search within .
To improve the ability to get data into a Splunk Cloud Platform, support was added for Universal Forwarders. For information about configuring forwarders, see Configure forwarders to send SOAR data to your Splunk deployment.
Configure to forward data to Splunk Cloud Platform
Integrating with Splunk Cloud Platform requires the following actions:
- Configure Universal Forwarders and a Universal Forwarder Credentials Package. See Configure forwarders to send SOAR data to your Splunk deployment.
Reindex data to make newly added information searchable
You can reindex all of your data.
Reindexing will send all your SOAR data to your Splunk Enterprise or Splunk Cloud Platform deployment again, which can result in duplicated data. To prevent duplicates, make sure to delete existing objects from all forwarder groups before reindexing. See How indexing works in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.
PREVIOUS Customize email templates in |
NEXT Configure forwarders to send SOAR data to your Splunk deployment |
This documentation applies to the following versions of Splunk® SOAR (Cloud): current
Feedback submitted, thanks!