<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Renaming index for data coming from universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439829#M76708</link>
    <description>&lt;P&gt;Hi @niketnilay ,&lt;/P&gt;

&lt;P&gt;The inputs.conf belongs to other customers. we have access to our own indexers. we don't use deployment server as they have huge number of hosts. &lt;BR /&gt;
Thanks for the link. helpful !! &lt;/P&gt;</description>
    <pubDate>Mon, 16 Jul 2018 19:51:01 GMT</pubDate>
    <dc:creator>nawazns5038</dc:creator>
    <dc:date>2018-07-16T19:51:01Z</dc:date>
    <item>
      <title>Renaming index for data coming from universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439827#M76706</link>
      <description>&lt;P&gt;We have data coming from lots of universal forwarders and it has various sources and sourcetypes and sending data only to a single index. &lt;BR /&gt;
we don't have access to  inputs.conf. &lt;BR /&gt;
How can we redirect the data to a different index. &lt;BR /&gt;
Can we use transforms.conf to work on that particular index (i,e changing index name for data based only on existing index )&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 18:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439827#M76706</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-07-16T18:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Renaming index for data coming from universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439828#M76707</link>
      <description>&lt;P&gt;@nawazns5038, what do you mean by not having access to inputs.conf. How will you have access to props.conf and transforms.conf otherwise?&lt;/P&gt;

&lt;P&gt;Ideally, you should send the data to correct index using inputs.conf (pushed to UF through a deployment server). However, on Indexer or HF, you can route data to specific index based on regular expression matches. Please refer to the following documentation:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes#Route_specific_events_to_a_different_index"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setupmultipleindexes#Route_specific_events_to_a_different_index&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 18:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439828#M76707</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-07-16T18:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: Renaming index for data coming from universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439829#M76708</link>
      <description>&lt;P&gt;Hi @niketnilay ,&lt;/P&gt;

&lt;P&gt;The inputs.conf belongs to other customers. we have access to our own indexers. we don't use deployment server as they have huge number of hosts. &lt;BR /&gt;
Thanks for the link. helpful !! &lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 19:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Renaming-index-for-data-coming-from-universal-forwarder/m-p/439829#M76708</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-07-16T19:51:01Z</dc:date>
    </item>
  </channel>
</rss>

