<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change index name of metrics data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712531#M117688</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&lt;/P&gt;&lt;P&gt;As I’ve tried to explain right from the beginning, It has been metric date all the time, why the default defined (event) index name had to be changed to a metric index name, which now works as a charm on the HF, so it was all durable and works perfectly.&lt;/P&gt;&lt;P&gt;Thanks for all your input- they helped me to focus on the details here&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All the best&lt;/P&gt;</description>
    <pubDate>Tue, 25 Feb 2025 21:05:48 GMT</pubDate>
    <dc:creator>BTrust</dc:creator>
    <dc:date>2025-02-25T21:05:48Z</dc:date>
    <item>
      <title>Change index name of metrics data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712298#M117638</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have a challenge, which i after many considerations have made a decision to, which indeed also have some consequences.&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I’m a (Splunk) consultant for a company who have hundreds of of customers around the world, whom I finally convinced to get a dedicated Logging &amp;amp; Monitoring system - and long story short, after a longer PoC, Splunk was chosen.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Now to the challenge with all these customers, who pretty much all use more or less the same SW platform created by the company i work for, and which produces both Events and Metrics (why your app is in the picture).&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;To limit the massive amount of App management, along with GDPR and what not, each customer get ONE index defined as default, but each have 4 indexes, a set of summary indexes and likewise ordinary indexes - 1 event and 1 metrics in each set.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When installing the UF on each customer, each get one default (event) index set in inputs.conf, this way all Events ends up in the right index, but not Metrics.&lt;/DIV&gt;&lt;DIV&gt;All indexes are following a strict naming convention in which an &amp;lt;customer id&amp;gt;_e_&amp;lt;some more&amp;gt; indicates ‘Events’ and vise versa _m_ their Metrics index.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So far so good!&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Using the great app ‘&lt;A class="" href="https://splunkbase.splunk.com/app/6492/" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN class=""&gt;Multi-Metric Perfmon&lt;/SPAN&gt;&lt;/A&gt;’, and defining the index on the UF (very unwanted solution) data goes stright through the HF to the IDX server as expected.&lt;/DIV&gt;&lt;DIV&gt;This solution will demand administration of individual apps per customer, which is a NO-GO.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Now - this raises the challenge, which I basically don’t understand why it becomes a challenge.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;What I’ve done to circumvent this issue about multi-management hundreds of apps, is controlling everything by sourcetype, and let the HF do the switching of index between Event/Metrics depending on the incoming sourcetype.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So basically use props.conf to catch any sourcetype with ‘metrics’ in its name, and then use transforms.conf REGEX to change the index name from the default ‘&amp;lt;bla bla&amp;gt;_e_&amp;lt;bla&amp;gt;’ to ‘&amp;lt;bla bla&amp;gt;_m_&amp;lt;bla&amp;gt;’, which works perfect, except I get this error message in Splunk, and NO data in the index, as when the index is set directly on the HF (using the ‘Mutti-metric Parfmon’ &amp;nbsp;inputs.conf to define the index name):&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;The metric event is not properly structured, source=LogicalDisk, sourcetype=Perfmon, host=w_00001_test_bjd_0001, index=c_00001_no_emea_&lt;STRONG&gt;m&lt;/STRONG&gt;_pub. Metric event data without a metric name and properly formated numerical values are invalid and cannot be indexed. Ensure the input metric data is not malformed, have one or more keys of the form "metric_name:&amp;lt;metric&amp;gt;" (e.g..."metric_name:cpu.idle") with corresponding floating point values.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I’m far from a Splunk Metrics expert though I’ve worked intensively with Splunk for 10 years, metrics just never came my way till now.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So I don’t know what happens between the UF and the IDX, except that if (as said) defining the index on the UF in the app inputs.conf all works just fine.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Whereas if I don’t define an index in the apps inputs, it will go with the default index, which is an Event index, why I let the HF change the index name to its corresponding _m_ metrics index.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Using Splunk _internal Metrics I can see the data being transferred to the indexer using the correct index name, but here it stops, and I get above message.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Can you explain this behaviour?&lt;/DIV&gt;&lt;DIV&gt;And more over how to fix this?&lt;/DIV&gt;&lt;DIV&gt;What is happening on the HF - that I don’t see, since data is now rejected though pointed to the correct index?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;You input and/or help would be most appreciated&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 23 Feb 2025 00:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712298#M117638</guid>
      <dc:creator>BTrust</dc:creator>
      <dc:date>2025-02-23T00:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Change index name of metrics data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712312#M117639</link>
      <description>&lt;P&gt;One cannot redirect event data to a metrics index.&amp;nbsp; Doing so will produce the error message you see.&amp;nbsp; Data in a metrics index must be in a specific format - that is what makes them so fast.&amp;nbsp; It is possible, however, to convert an event into metrics at index time.&amp;nbsp; See &lt;STRONG&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Metrics/L2MConfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Metrics/L2MConfiguration&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I must point out a fundamental flaw in the plan to have only two indexes for each customer.&amp;nbsp; It means that all data will have the same retention period and (more seriously) all data will be visible to all users in that company.&amp;nbsp; It's unlikely all of a company's data will have the same security and retention requirements.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2025 17:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712312#M117639</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-02-23T17:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Change index name of metrics data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712314#M117640</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Many thanks for your input.&lt;/P&gt;&lt;P&gt;I think there were a few things you got wrong here.&lt;/P&gt;&lt;P&gt;Let's begin from scratch here:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The metrics are collected on Windows UF and sent via a HF to the final IDX.&lt;OL&gt;&lt;LI&gt;If the index name is defined (inputs.conf) in&amp;nbsp; the collection app on the UF, and sent directly through the HF to the IDX, and works perfect.&lt;/LI&gt;&lt;LI&gt;If NO index name is defined in above app, the UF default defined index will be used as destination, but here I have defined a props on the HF to "catch" sourcetypes containing 'metrics', and here convert (rename) the incoming (default) index name to its coresponding metric index name (aka from _e_ to _m_ type), and rename part works just fine, but something seems to happen to raw metrics data, as the indexer reject them now - THOUGH it's exactly the same data as in point 1. above.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;About your last concern with two indexes, we have additional indexes if needed for different levels of data categories, BUT said that Spunk finaly works fine with search filters, so a lot can be handeled this way - but thanks for you great inputs her &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Everything works perfect when col&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Sun, 23 Feb 2025 17:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712314#M117640</guid>
      <dc:creator>BTrust</dc:creator>
      <dc:date>2025-02-23T17:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Change index name of metrics data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712322#M117641</link>
      <description>&lt;P&gt;I got nothing wrong.&amp;nbsp; Step 2 is not possible.&amp;nbsp; Yes, you can change the name of the index, but an event cannot be written to a metric index without conversion.&amp;nbsp; The fact that step 1 works perfectly tells me the data is an event rather than a metric.&lt;/P&gt;&lt;P&gt;Splunk has a tendency to overload terms.&amp;nbsp; in this case, "metric" can refer to a numeric value in an event or it can refer to a specific format of data (also numeric) that only a metric index can store.&amp;nbsp; it's the format (or lack of it) that's causing the error message.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 01:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712322#M117641</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-02-24T01:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Change index name of metrics data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712531#M117688</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&lt;/P&gt;&lt;P&gt;As I’ve tried to explain right from the beginning, It has been metric date all the time, why the default defined (event) index name had to be changed to a metric index name, which now works as a charm on the HF, so it was all durable and works perfectly.&lt;/P&gt;&lt;P&gt;Thanks for all your input- they helped me to focus on the details here&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All the best&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 21:05:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-index-name-of-metrics-data/m-p/712531#M117688</guid>
      <dc:creator>BTrust</dc:creator>
      <dc:date>2025-02-25T21:05:48Z</dc:date>
    </item>
  </channel>
</rss>

