<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarding data by identified index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433970#M75823</link>
    <description>&lt;P&gt;That means you are receiving the events but your inputs is telling them to go to index=secure and you don't have the index configured. What does your architecture look like? You would need that index configured at your indexer (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes#Create_and_edit_indexes"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes#Create_and_edit_indexes&lt;/A&gt;). &lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2019 15:44:50 GMT</pubDate>
    <dc:creator>mdsnmss</dc:creator>
    <dc:date>2019-05-01T15:44:50Z</dc:date>
    <item>
      <title>forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433965#M75818</link>
      <description>&lt;P&gt;I have a Splunk Enterprise, which collects 3 different indexed data, I need to forward only one of them, how can I do this? &lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 11:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433965#M75818</guid>
      <dc:creator>makhambayeva</dc:creator>
      <dc:date>2019-04-29T11:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433966#M75819</link>
      <description>&lt;P&gt;Hi @makhambayeva,&lt;BR /&gt;
What does your inputs.conf look like? What kind of data are you collecting and how are you collecting it? Is the data you are looking to collect split out between different files/sources or combined into one? Depending on those answers there may be different solutions.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 12:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433966#M75819</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-04-29T12:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433967#M75820</link>
      <description>&lt;P&gt;Also, provide how data is currently being ingested and how you want it to be (with some examples).&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 15:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433967#M75820</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-04-29T15:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433968#M75821</link>
      <description>&lt;P&gt;I have two flows from different protective equipments (FortiGate, FortiSandox), which are sending data on certain tcp ports, and one auth log-file, which is stored on Splunk server on "/var/log/secure" directory. There are 3 diferent sources, but when I configure forwarding from web console, it send only information came from ports. How i need to configure inputs.conf in order to send data from certain  file?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 03:25:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433968#M75821</guid>
      <dc:creator>makhambayeva</dc:creator>
      <dc:date>2019-04-30T03:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433969#M75822</link>
      <description>&lt;P&gt;to be exact, splunk forwards log-file to indexer, but , according to my thoughts, indexer cannot receive them. i see warning "received event from unconfigured/disabled/deleted index=secure. So far received events from missing index"&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 03:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433969#M75822</guid>
      <dc:creator>makhambayeva</dc:creator>
      <dc:date>2019-04-30T03:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433970#M75823</link>
      <description>&lt;P&gt;That means you are receiving the events but your inputs is telling them to go to index=secure and you don't have the index configured. What does your architecture look like? You would need that index configured at your indexer (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes#Create_and_edit_indexes"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes#Create_and_edit_indexes&lt;/A&gt;). &lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 15:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433970#M75823</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-05-01T15:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding data by identified index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433971#M75824</link>
      <description>&lt;P&gt;There is also a setting in indexes.conf that specified a lastChanceIndex. It is explained here: &lt;A href="https://answers.splunk.com/answers/594449/what-happens-when-the-forwarder-is-configured-to-s.html"&gt;https://answers.splunk.com/answers/594449/what-happens-when-the-forwarder-is-configured-to-s.html&lt;/A&gt;. If your data has an index specified it can't get to it would go to what you specify here. People often configure it for &lt;CODE&gt;main&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 15:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-data-by-identified-index/m-p/433971#M75824</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-05-01T15:47:43Z</dc:date>
    </item>
  </channel>
</rss>

