<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/669947#M79992</link>
    <description>&lt;P&gt;There might be several things wrong, not the destination index configuration. As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; already said - please create a new thread describing your configuration and problem. The problem in this thread has already been resolved. Let's keep the Answers nice and tidy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Nov 2023 00:49:22 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-11-28T00:49:22Z</dc:date>
    <item>
      <title>Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/598548#M76846</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've just installed the&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/742/" target="_self"&gt;Splunk Add-on for Microsoft Windows&amp;nbsp;&lt;/A&gt;and I will be collecting data from UFs that forward first to a HF and then to an indexing cluster.&amp;nbsp; The app will be deployed to multiple UFs via deployment server.&amp;nbsp; I only want to collect data from the machines that the UFs are installed on.&lt;/P&gt;&lt;P&gt;I see that there is no way to specify within inputs.conf which index to send the data to.&amp;nbsp; I've read the documentation but I still don't understand how.&amp;nbsp; I've even found &lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-indexes-conf-has-been-removed/m-p/393006" target="_self"&gt;this post&lt;/A&gt; which discusses the same topic but doesn't really provide me with an answer that I understand (sends me to documentation for older version of the add-on).&lt;/P&gt;&lt;P&gt;Could somebody please give me a push in the right direction?&lt;/P&gt;&lt;P&gt;Thank you and best regards,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 18:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/598548#M76846</guid>
      <dc:creator>andrewtrobec</dc:creator>
      <dc:date>2022-05-19T18:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/598552#M76847</link>
      <description>&lt;P&gt;Specify the destination index in inputs.conf.&amp;nbsp; Simply insert a new line in the appropriate stanza with &lt;FONT face="courier new,courier"&gt;index =&lt;/FONT&gt; followed by the name of index.&amp;nbsp; See the examples at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/Configuration#Configure_inputs.conf" target="_blank"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/Configuration#Configure_inputs.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 18:44:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/598552#M76847</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-05-19T18:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/598572#M76848</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;thank you so much, I don't know how I didn't figure that out.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 20:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/598572#M76848</guid>
      <dc:creator>andrewtrobec</dc:creator>
      <dc:date>2022-05-19T20:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/668472#M79952</link>
      <description>&lt;P&gt;This worked for me when I was testing on a personal Windows laptop, but the official system I use is 2015 Windows 10 Pro, which is much older. I had to download an older 7.2.10 version of Splunk Universal Forwarder for it to even download. The logs are&amp;nbsp; being forwarded, but when I add the index line, nothing changes and the search for that index comes up empty. Could this be due to using an older universal forwarder version? Is there a different way to assign an index?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 22:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/668472#M79952</guid>
      <dc:creator>rosez2</dc:creator>
      <dc:date>2023-11-13T22:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/668534#M79953</link>
      <description>&lt;P&gt;This thread is over a year old with an accepted solution so the better way to get a response is to post a new question.&lt;/P&gt;&lt;P&gt;The old version s of Universal Forwarder support index names in inputs.conf exactly the same as newer versions.&amp;nbsp; The index must exist on the indexers, of course, and you must have access to it.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 13:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/668534#M79953</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-14T13:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/669937#M79991</link>
      <description>&lt;P&gt;I have the index in both the inputs.conf stanza, and I also added it to the Splunk Enterprise list of indexes. I don't understand why it worked on my Windows 10 Enterprise and my Kali Linux machines (for Kali I configured through command line), but not Windows 10 2015. I am sure that my steps for Windows 10 2015 and Windows 10 Enterprise are the exact same.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 22:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/669937#M79991</guid>
      <dc:creator>rosez2</dc:creator>
      <dc:date>2023-11-27T22:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/669947#M79992</link>
      <description>&lt;P&gt;There might be several things wrong, not the destination index configuration. As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; already said - please create a new thread describing your configuration and problem. The problem in this thread has already been resolved. Let's keep the Answers nice and tidy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 00:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Windows-How-do-I-specify-which-index/m-p/669947#M79992</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-28T00:49:22Z</dc:date>
    </item>
  </channel>
</rss>

