<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs are going to catch all index in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571712#M10155</link>
    <description>&lt;P&gt;Not specifically.&amp;nbsp; The files will be in directories under $SPLUNK_HOME/etc.&amp;nbsp; Use btool or the Linux find command to locate them (yes, it's most likely there will be more than one).&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool --debug inputs list&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;find $SPLUNK_HOME/etc -name inputs.conf&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 20 Oct 2021 18:56:18 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-10-20T18:56:18Z</dc:date>
    <item>
      <title>logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571679#M10152</link>
      <description>&lt;P&gt;We have configured the panorama management logs on syslog server correctly. While checking the pan logs on core search head logs are going to catch all index. Please suggest here for correct configuration to fix the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 15:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571679#M10152</guid>
      <dc:creator>hemantwcp7</dc:creator>
      <dc:date>2021-10-20T15:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571704#M10153</link>
      <description>&lt;P&gt;The catch-all index is used when the input does not specify an index.&amp;nbsp; Double-check indexes.conf on the syslog server and make sure every monitor stanza has a &lt;FONT face="courier new,courier"&gt;index=&lt;/FONT&gt; setting.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 17:49:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571704#M10153</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-20T17:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571709#M10154</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, I checked the available&amp;nbsp;&lt;SPAN&gt;indexes.conf&amp;nbsp;but i did not found&amp;nbsp;&amp;nbsp;monitor stanza section. Can you please specify the file location on linux OS ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 18:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571709#M10154</guid>
      <dc:creator>hemantwcp7</dc:creator>
      <dc:date>2021-10-20T18:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571712#M10155</link>
      <description>&lt;P&gt;Not specifically.&amp;nbsp; The files will be in directories under $SPLUNK_HOME/etc.&amp;nbsp; Use btool or the Linux find command to locate them (yes, it's most likely there will be more than one).&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool --debug inputs list&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;find $SPLUNK_HOME/etc -name inputs.conf&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 20 Oct 2021 18:56:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/571712#M10155</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-20T18:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572044#M10156</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;, On syslog server we have custom .conf file in syslog-ng directory where all palo alto logs coming on udp_port(10527) , tcp_port(10527) . In this file only i added the new pan source. Rest all pan sources from this conf are correctly landing to proper index on Splunk cloud except one new pan source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 16:25:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572044#M10156</guid>
      <dc:creator>hemantwcp7</dc:creator>
      <dc:date>2021-10-22T16:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572057#M10157</link>
      <description>&lt;P&gt;Or if they are supposed to go to a non-existant index (for example, specified when supplying event via HEC) if I remember correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 17:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572057#M10157</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-22T17:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572058#M10158</link>
      <description>&lt;P&gt;If you're using a UF to get the data from the syslog server to Splunk then .conf file should be somewhere in /opt/splunkforwarder/etc/ rather than in a syslog-ng directory.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 17:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572058#M10158</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-22T17:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: logs are going to catch all index</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572064#M10159</link>
      <description>&lt;P&gt;Are you using any kind of an intermediate syslog layer? (This syslog-ng you're speaking of)&lt;/P&gt;&lt;P&gt;Does it change/manipulate the events in any way? (For example I have in one of my environments heavily complicated rsyslog-based solution that in the end supplies events to splunk via HEC).&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 17:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-are-going-to-catch-all-index/m-p/572064#M10159</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-22T17:55:52Z</dc:date>
    </item>
  </channel>
</rss>

