<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you send the same event log to two different Indexes in the same app? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-you-send-the-same-event-log-to-two-different-Indexes-in-the/m-p/646733#M16570</link>
    <description>&lt;P&gt;so we have a Deployment Server with an application on there that already sends the three basic Windows Event logs (Application, Security, and System) to an Index say called EventLogs.&amp;nbsp; Can we in the same app have the same three logs be sent to a second Index say called EventLogs2?&lt;/P&gt;
&lt;P&gt;I know this may sound a bit crazy but this is just for troubleshooting and will be only implemented for a couple days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the inputs.conf stanzas look something like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[WinEventLog://System]&lt;BR /&gt;index=EventLogs&lt;BR /&gt;disabled = false&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[WinEventLog://System]&lt;BR /&gt;index=EventLogs2&lt;BR /&gt;disabled = false&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 13:19:12 GMT</pubDate>
    <dc:creator>Gregski11</dc:creator>
    <dc:date>2023-06-13T13:19:12Z</dc:date>
    <item>
      <title>Can you send the same event log to two different Indexes in the same app?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-you-send-the-same-event-log-to-two-different-Indexes-in-the/m-p/646733#M16570</link>
      <description>&lt;P&gt;so we have a Deployment Server with an application on there that already sends the three basic Windows Event logs (Application, Security, and System) to an Index say called EventLogs.&amp;nbsp; Can we in the same app have the same three logs be sent to a second Index say called EventLogs2?&lt;/P&gt;
&lt;P&gt;I know this may sound a bit crazy but this is just for troubleshooting and will be only implemented for a couple days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the inputs.conf stanzas look something like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[WinEventLog://System]&lt;BR /&gt;index=EventLogs&lt;BR /&gt;disabled = false&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[WinEventLog://System]&lt;BR /&gt;index=EventLogs2&lt;BR /&gt;disabled = false&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 13:19:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Can-you-send-the-same-event-log-to-two-different-Indexes-in-the/m-p/646733#M16570</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-06-13T13:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can you send the same Event Log to two different Indexes in the same app?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-you-send-the-same-event-log-to-two-different-Indexes-in-the/m-p/646734#M16571</link>
      <description>&lt;P&gt;I'd be interested in this as well.&amp;nbsp; However, you could have a scheduled job to export the logs to a file on the windows machine, the put a Monitor stanza in the inputs.conf to go to another index as a workaround.&amp;nbsp; Just trying to think of other ways just in case.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 22:44:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Can-you-send-the-same-event-log-to-two-different-Indexes-in-the/m-p/646734#M16571</guid>
      <dc:creator>paulcurry</dc:creator>
      <dc:date>2023-06-12T22:44:18Z</dc:date>
    </item>
  </channel>
</rss>

