splunk/splunk-ansible

Setup index, transform, RBAC on splunk_standalone?

juju4 opened this issue · 1 comments

juju4 commented

Thanks for the collection.
I'm using it with role splunk_standalone but have difficulties how to set up few things.
Data is ingested from port 9997 and for, now everything goes to main index.

It would be a nice example to add to documentation as this is common setup IMHO.

juju4 commented

I managed to split index with multiple splunk HEC and matching index as defined in /opt/splunk/etc/apps/search/local/inputs.conf and /opt/splunk/etc/apps/search/local/indexes.conf but I believe this needs to be set outside of role as hec variable seems to define only a single entry.