If you do not set a specific index for a search, Splunk will use its main or default index (this might vary depending on the role(s) assigned to you and the default indexes currently configured). As a Splunk administrator, you can use Splunk Web, the CLI, or edit the
indexes.conf file to create an unlimited number of additional indexes.
There are three main reasons why you might want (or need) to consider setting up more indexes in your Splunk environment. These are as follows: