uberAgent

How to Change uberAgent’s Splunk Index Names

By default, uberAgent sends the data it collects to the Splunk index uberagent. The Experience Score and Security Score results are stored automatically in the uberAgent score indexes score_uberagent_uxm and score_uberagent_esa.

How the indexes are created

The indexes uberagent, score_uberagent_uxm, and score_uberagent_esa are created in the Splunk indexer app uberAgent_indexer. Their definitions are configured in the file default\indexes.conf.

How to change the main index name

If you want to change the index name uberAgent sends its data to, you need to do so in the following places:

  • indexes.conf (see above)
  • uberAgent configuration (see below)
  • macros.conf (see below)
  • eventtypes.conf (see below)

Note

If your custom uberAgent main index name starts with “uberagent”, you don’t need to update the macros.conf and eventtypes.conf files, since the default definition includes a wildcard that matches any index that starts with uberagent, e.g., uberagent_custom.

uberAgent configuration

The index uberAgent sends the collected data to can be configured in uberAgent’s configuration with the setting Index.

Macros.conf

The index used by the dashboards is configured through the uberAgent_index stanza in the macros.conf file of the uberAgent UXM search head app. The default is as follows:

[uberAgent_index]
definition = uberagent*
<!--NeedCopy-->

Eventtypes.conf

The index used by the uberAgent_index_query event type is configured through the uberAgent_index_query stanza in the eventtypes.conf file of the dashboard search head apps. The default is as follows:

[uberAgent_index_query]
search = index=uberagent*
<!--NeedCopy-->

How to change the score index names

If you want to change the names of the two score indexes, you need to update the following:

  • indexes.conf (see above)
  • macros.conf (see below)

Both Splunk search head apps for uberAgent UXM and uberAgent ESA ship a macros.conf file that specifies the respective index for the score data. Scores are calculated automatically in Splunk, so you do not need to adjust the agent configuration.

The index used to store the Experience Score results is configured in the macros.conf file of the uberAgent UXM search head app.

[uberAgentUXM_score_index]
definition = score_uberagent_uxm
<!--NeedCopy-->

The index used to store the Security Score results is configured in the macros.conf file of the uberAgent ESA search head app.

[uberAgentESA_score_index]
definition = score_uberagent_esa
<!--NeedCopy-->

Important

The search macros for the score-related indexes must not include a wildcard. Both macro definitions must explicitly refer to a valid index. Using a wildcard or defining a non-existent index results in empty Experience Score or Security Score dashboards.

How to Change uberAgent’s Splunk Index Names