Skip to content

Add a Splunk Index

When to Create a New Index

A new index requires a material difference in retention, data classification, access controls, residency, capacity ownership, or ingestion behavior. A new device type by itself is usually handled through metadata in an existing index.

Request Process

Provide the data owner, classification, source types, regions, expected daily/peak volume, retention requirement, access groups, routing path, parsing expectations, dashboards/searches, alerts, and capacity approval.

Configure Data Input

After approval, create the index and role mappings through the managed configuration workflow. Update syslog, trap, file, or Universal Forwarder routing as applicable. Never place HEC tokens or forwarding credentials in this repository.

Verify Data

Send non-sensitive representative data and confirm regional instance, index, timestamp, host, source/sourcetype, metadata enrichment, searchability, and authorized/unauthorized access behavior.

Access Control

Map the index to least-privileged roles and the approved MyID groups. Document the owner and access-review process, then update the logging and operations pages.