Professional Documents
Culture Documents
For detailed examples of configuring indexes, see indexes.conf.example in the Splunk Enterprise Admin Manual.
Indexes by app
You might see additional or fewer indexes, depending on your capabilities and which apps you have installed. The
following are non-system indexes.
Does not contain event data. Used behind the scenes for routing to your
ubaroute
Splunk_TA_ueba UBA target.
Index deployment
Splunk Enterprise Security includes a tool to gather the indexes.conf and index-time props.conf and transforms.conf
settings from all enabled apps and add-ons on the search head and assemble them into one add-on. For more details,
see Deploy add-ons included with Splunk Enterprise Security in this manual.
26