hashicorp / hashicorp/terraform-docs-common

Splunk Add-on : App sends data to both main and configured index

Open
#765 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Makefile
Stars
36
Forks
133
PR merge metrics
No merged PRs in 30d

Description

Hi,
I have installed the add-on to our Splunk Cloud instance however the app does not allow for any index configuration so it uses by default main. The splunk Cloud ACS API does not allow for input configuration changes such as this to be performed via the API.

Is there some step or interaction that I am unaware of that will allow me to change the index the app uses to anything of my choosing rather than defaulting to main.

Edit: I was able to change the index in the data inputs > HCP Terraform for Splunk > Index setting. However having changed that setting it is still sending data into the main index. Both indexes are receiving the same data, doubling out license consumption for the same data source

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the issue's reproduction details in Splunk Cloud: the data inputs > HCP Terraform for Splunk > Index setting and the reported ACS API limitation. Verify whether changing that setting still sends identical data to both the configured index and main. Done means the cause and supported remediation are established or the limitation is documented.

Written by the indexing model from the issue text.

Assessment

Domain
observability
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.