Add a Splunk Index
When to Create a New Index
A new index requires a material difference in retention, data classification, access controls, residency, capacity ownership, or ingestion behavior. A new device type by itself is usually handled through metadata in an existing index.
Request Process
Provide the data owner, classification, source types, regions, expected daily/peak volume, retention requirement, access groups, routing path, parsing expectations, dashboards/searches, alerts, and capacity approval.
Configure Data Input
After approval, create the index and role mappings through the managed configuration workflow. Update syslog, trap, file, or Universal Forwarder routing as applicable. Never place HEC tokens or forwarding credentials in this repository.
Verify Data
Send non-sensitive representative data and confirm regional instance, index, timestamp, host, source/sourcetype, metadata enrichment, searchability, and authorized/unauthorized access behavior.
Access Control
Map the index to least-privileged roles and the approved MyID groups. Document the owner and access-review process, then update the logging and operations pages.