<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why can't Splunk_TA_windows redirect to a custom index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589756#M103393</link>
    <description>&lt;P&gt;Thank you everyone for all the help, realized the deployment was pushing successfully and after getting access to the servers. Noticed that the deployment server wasn't triggering restarts to apply the conf changes.&lt;BR /&gt;&lt;BR /&gt;The issue ended up being a serverclass.conf configuration where an entry for restartSplunkd = true... was instead restartSplunkD = true&lt;BR /&gt;&lt;BR /&gt;The capital D was halting and splunkd restarts on the windows machines so the new configurations were never applied.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Mar 2022 22:56:28 GMT</pubDate>
    <dc:creator>rlaan</dc:creator>
    <dc:date>2022-03-18T22:56:28Z</dc:date>
    <item>
      <title>Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589392#M103362</link>
      <description>&lt;P&gt;I have added the latest version of Splunk_TA_windows to my environment using a deployment server.&lt;BR /&gt;&lt;BR /&gt;The app has been pushed to all windows machines, the search heads and the heavy forwarders.&lt;BR /&gt;&lt;BR /&gt;I have only been receiving data into the "Main" index and be unsuccessful at redirecting the data to our preferred collection points index =&amp;nbsp; wineventlog.&lt;BR /&gt;&lt;BR /&gt;on the deployment server i have created a&amp;nbsp; Splunk_TA_windows/local/inputs.conf file containing the following.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[WinEventLog://ForwardedEvents]
index = wineventlog
disabled = 0

[WinEventLog://Application]
index = wineventlog
disabled = 0

[WinEventLog://System]
index = wineventlog
disabled = 0

[XmlWinEventLog]
index = wineventlog

[WinEventLog]
index = wineventlog
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I am primarily a linux guy for splunk admin and only have 1 windows host monitored at the moment (all windows events are forwarded to and collected from this node), is there something that needs to be done differently to redirect the index for this applications? Next consideration I have is using props/transforms to change the index although am worried about the hardware impact of that on 5 million events a day.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 18:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589392#M103362</guid>
      <dc:creator>rlaan</dc:creator>
      <dc:date>2022-03-16T18:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_windows can't redirect to a custom index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589393#M103363</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/121623"&gt;@rlaan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;id you deployed the TA-Windows modified as you said to all Windows Universal Forwarder, you should have events in the wineventlog index.&lt;/P&gt;&lt;P&gt;If not, you could also override index on Indexers or (when present) on Heavy Forwarders.&lt;/P&gt;&lt;P&gt;To override index you have to create a props.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype1]
TRANSFORMS-index = overrideindex

[your_sourcetype2]
TRANSFORMS-index = overrideindex

[your_sourcetype3]
TRANSFORMS-index = overrideindex&lt;/LI-CODE&gt;&lt;P&gt;and a transforms.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[overrideindex]
DEST_KEY =_MetaData:Index
REGEX = .
FORMAT = wineventlog&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 18:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589393#M103363</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-16T18:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589413#M103368</link>
      <description>&lt;P&gt;It doesn't work that way. You can have a default settings in [default] stanza but you can't use general "input type" stanza.&lt;/P&gt;&lt;P&gt;So you need to either define a default setting or add index parameter to each individual input.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 21:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589413#M103368</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-16T21:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589417#M103369</link>
      <description>&lt;P&gt;if the default stanza is added would this cause all things sent to main to go to the new index (potentially from unrelated applications?) I am curious to potential environmental level effects as the application is deployed on the heavy forwarders and could effect all inputs.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 21:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589417#M103369</guid>
      <dc:creator>rlaan</dc:creator>
      <dc:date>2022-03-16T21:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589419#M103370</link>
      <description>&lt;P&gt;Short answer - it could.&lt;/P&gt;&lt;P&gt;Long answer - it depends on how other inputs are defined. But the typical approach is to explicitly define destination index per input. This way you avoid such unexpected changes in behaviour.&lt;/P&gt;&lt;P&gt;BTW, remember that efective config depends on config files priority so such "default" setting could theoretically be overwritten by another default setting.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 21:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589419#M103370</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-16T21:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589422#M103371</link>
      <description>&lt;P&gt;How would i go about adding a "&lt;SPAN&gt;add index parameter to each individual input" I thought that was already what i was doing with the individual stanza such as&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://Application]
index = wineventlog&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I guess there is a gap in my understanding of how the monitors are defined on windows, i have tried adding index=wineventlog to all stanza present within the default/inputs.conf into my local version without any events being sent to the new index.&lt;BR /&gt;&lt;BR /&gt;Many windows servers are sending data to the single universal forward before passing it into splunk, is this aggregation using window tools possibly an issue with how the indexes are defined?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 22:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589422#M103371</guid>
      <dc:creator>rlaan</dc:creator>
      <dc:date>2022-03-16T22:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589514#M103373</link>
      <description>&lt;P&gt;OMG, my bad. I didn't notice that you do have the index specified under each input as well. I suppose I noticed the entries in the "genre" stanzas and assumed you didn't put them there.&lt;/P&gt;&lt;P&gt;Did you check with btool what's your effective input conifg?&lt;/P&gt;&lt;PRE&gt;c:\program files\splunkuniversalforwarder\bin\splunk btool inputs list --debug&lt;/PRE&gt;&lt;P&gt;The installation path might of course differ, it might be c:\program files\splunk for older forwarder versions and if you installed it somewhere else completely, look for it there &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 13:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589514#M103373</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-17T13:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589596#M103384</link>
      <description>&lt;P&gt;Did some more testing, it appears the windows forwarder had a locally configured app&amp;nbsp;&lt;BR /&gt;SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf&lt;BR /&gt;&lt;BR /&gt;Containing the following entry&lt;BR /&gt;[WinEventLog://ForwardedEvents]&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;current_only = 0&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;&lt;BR /&gt;I had a windows admin remove the extra configuration in the above local app and added the same entry to the Splunk_TA_windows/local/inputs.conf on the deployment server and confirmed it was pushed to the windows forwarder.&lt;BR /&gt;&lt;BR /&gt;This broke the data inputs, so now i am wondering why the Splunk_TA_windows app pushed via deployment server doesn't seem to be detected by the universal forwarder. While the locally added file in&amp;nbsp;apps\SplunkUniversalForwarder\local\inputs.conf redirected the forwarded events. Anyone have an idea on what to check to get the deployment server managed applications to function on the forwarder?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 21:51:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589596#M103384</guid>
      <dc:creator>rlaan</dc:creator>
      <dc:date>2022-03-17T21:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589756#M103393</link>
      <description>&lt;P&gt;Thank you everyone for all the help, realized the deployment was pushing successfully and after getting access to the servers. Noticed that the deployment server wasn't triggering restarts to apply the conf changes.&lt;BR /&gt;&lt;BR /&gt;The issue ended up being a serverclass.conf configuration where an entry for restartSplunkd = true... was instead restartSplunkD = true&lt;BR /&gt;&lt;BR /&gt;The capital D was halting and splunkd restarts on the windows machines so the new configurations were never applied.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 22:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589756#M103393</guid>
      <dc:creator>rlaan</dc:creator>
      <dc:date>2022-03-18T22:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't Splunk_TA_windows redirect to a custom index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589763#M103394</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/121623"&gt;@rlaan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the Contributors;-)&lt;/P&gt;</description>
      <pubDate>Sat, 19 Mar 2022 07:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-Splunk-TA-windows-redirect-to-a-custom-index/m-p/589763#M103394</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-19T07:08:52Z</dc:date>
    </item>
  </channel>
</rss>

