<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputs.conf and destination index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60426#M11980</link>
    <description>&lt;P&gt;Try those commands&lt;BR /&gt;
/opt/splunk/bin/splunk stop &lt;BR /&gt;
/opt/splunk/bin/splunk clean eventdata [imaging|main]&lt;BR /&gt;
/opt/splunk/bin/splunk start&lt;/P&gt;</description>
    <pubDate>Fri, 14 Sep 2012 14:42:19 GMT</pubDate>
    <dc:creator>sieutruc</dc:creator>
    <dc:date>2012-09-14T14:42:19Z</dc:date>
    <item>
      <title>inputs.conf and destination index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60423#M11977</link>
      <description>&lt;P&gt;this stanza works and indexes events:&lt;/P&gt;

&lt;P&gt;[monitor://\Njros1bva0624\c_root$\Program Files\eClarifyPM\eClarifyPM.log]&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;host = ECLARIFYLOG_HOST&lt;/P&gt;

&lt;P&gt;alwaysOpenFile = 1&lt;/P&gt;

&lt;P&gt;sourcetype = ECLARIFYLOG&lt;/P&gt;

&lt;P&gt;If shutdown splunk, I clean the indexes, thenchange the above stanza to the stanza below and then restart splunk , this stanza does not result in any indexing of events:&lt;/P&gt;

&lt;P&gt;[monitor://\Njros1bva0624\c_root$\Program Files\eClarifyPM\eClarifyPM.log]&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;host = ECLARIFYLOG_HOST&lt;/P&gt;

&lt;P&gt;alwaysOpenFile = 1&lt;/P&gt;

&lt;P&gt;sourcetype = ECLARIFYLOG&lt;/P&gt;

&lt;P&gt;index=imaging]&lt;/P&gt;

&lt;P&gt;The index, imaging, does exist.&lt;/P&gt;

&lt;P&gt;Please advise&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 14:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60423#M11977</guid>
      <dc:creator>peter_gianusso</dc:creator>
      <dc:date>2012-09-14T14:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf and destination index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60424#M11978</link>
      <description>&lt;P&gt;I think you should use search as: index=imaging .... Or you can go to Access Control-&amp;gt;Role and add that index into your user's selected indexes. If not, try to restart again.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 14:26:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60424#M11978</guid>
      <dc:creator>sieutruc</dc:creator>
      <dc:date>2012-09-14T14:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf and destination index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60425#M11979</link>
      <description>&lt;P&gt;the problem isn't a search.  it doesn't index any files when I add the index=imaging.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 14:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60425#M11979</guid>
      <dc:creator>peter_gianusso</dc:creator>
      <dc:date>2012-09-14T14:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf and destination index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60426#M11980</link>
      <description>&lt;P&gt;Try those commands&lt;BR /&gt;
/opt/splunk/bin/splunk stop &lt;BR /&gt;
/opt/splunk/bin/splunk clean eventdata [imaging|main]&lt;BR /&gt;
/opt/splunk/bin/splunk start&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 14:42:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60426#M11980</guid>
      <dc:creator>sieutruc</dc:creator>
      <dc:date>2012-09-14T14:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: inputs.conf and destination index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60427#M11981</link>
      <description>&lt;P&gt;Now I understand your comments about user's selected indexes..you need to add it to the role's default indexes..bingo!!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 18:22:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputs-conf-and-destination-index/m-p/60427#M11981</guid>
      <dc:creator>peter_gianusso</dc:creator>
      <dc:date>2012-09-14T18:22:17Z</dc:date>
    </item>
  </channel>
</rss>

