#
Update Splunk Index
Danger, Will Robinson
Failure to update the index to the correct setting will cause no devices to be available in Splunk Enterprise Security.
The index definition is set by a search macro.
The aws-index-value
search macro is included with Splunk Enterprise Security and is set to aws_security by default.
#
How to update
- (In Splunk Enterprise Security) Navigate to Configure > General > General Settings.
- From the "App" dropdown select
SA-AwsAssets
. - Update the SA-AwsAssets Index definition and click "Save."
- Navigate to Settings > Advanced Search > Search Macros.
- From the "App" dropdown choose
SA-AwsAssets
. - Set the "Owner" dropdown to
any
. - Click the macro named
sa_aws_assets_index
to update the index definition.